CVE-2025-22621

Privilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAR

Severity
Medium 6.4
CVSS 3.1
Exploited
Not listed
EPSS
0.003
17.9th percentile
Discovered by
Not disclosed
Published
Jan 7, 2025
Assigned by splunk

Description

In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roles.

Weakness: CWE-269

Affected products

Vendor Product Category Matched by
Cisco Splunk Apps & Add-ons SIEM & Log Management affected-vendor
Vendor-reported products (1)
  • Splunk · Splunk App for SOAR

Credit

Gabriel Nitu, Splunk

Something wrong here?