CVE-2023-22943
Published on: Not Yet Published
Last Modified on: 02/23/2023 04:17:00 PM UTC
Certain versions of Add-on Builder from Splunk contain the following vulnerability:
In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectly revert to using HTTP to connect after a failure to connect over HTTPS occurs. The vulnerability affects AoB and apps that AoB generates when using the REST API Modular Input functionality through its user interface. The vulnerability also potentially affects third-party apps and add-ons that call the *cloudconnectlib.splunktacollectorlib.cloud_connect_mod_input* Python class directly.
- CVE-2023-22943 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Splunk - Splunk Add-on Builder version < 4.1.2
- Affected Vendor/Software:
Splunk - Splunk CloudConnect SDK version < 3.1.3
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
SVD-2023-0213 | Splunk Vulnerability Disclosure | advisory.splunk.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Splunk | Add-on Builder | All | All | All | All |
Application | Splunk | Cloudconnect Software Development Kit | All | All | All | All |
- cpe:2.3:a:splunk:add-on_builder:*:*:*:*:*:*:*:*:
- cpe:2.3:a:splunk:cloudconnect_software_development_kit:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-22943 | 2023-02-14 18:38:33 |