Cleartext transmission of sensitive information in Splunk CloudConnect SDK and Splunk Add-on Builder - CVE-2023-22943
Published: February 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software can send requests to third-party APIs through the REST API Modular Input using unencrypted HTTP protocol instead of HTTPS. A remote attacker with ability to intercept network traffic can gain access to sensitive data.
Affected software
Splunk Add-on Builder
How to mitigate CVE-2023-22943
Splunk Add-on Builder - update to 4.1.2