CVE-2025-22621
Privilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAR
Severity
Medium 6.4
CVSS 3.1
Exploited
Not listed
EPSS
0.003
17.9th percentile
Discovered by
Not disclosed
Published
Jan 7, 2025
Assigned by splunk
Description
In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roles.
Weakness: CWE-269
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Apps & Add-ons | SIEM & Log Management | affected-vendor |
Vendor-reported products (1)
- Splunk · Splunk App for SOAR
Credit
Gabriel Nitu, Splunk