Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Privilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAR
Vulnerability Description
In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roles.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
特权管理不恰当
Vulnerability Title
Splunk App for SOAR 安全漏洞
Vulnerability Description
Splunk App for SOAR是美国Splunk公司的一套数据收集分析软件。 Splunk App for SOAR 1.0.67及之前版本存在安全漏洞,该漏洞源于访问控制不当。
CVSS Information
N/A
Vulnerability Type
N/A