#VU85937 Inclusion of Sensitive Information in Log Files in Splunk Add-on Builder - CVE-2023-46231
Published: January 31, 2024
Splunk Add-on Builder
Splunk Inc.
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to application writes user session tokens to its internal log files when the user visits the Splunk Add-on Builder or when builds or edits a custom app or add-on. A local user can read the log files and gain access to sensitive data.