In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-ID: CWE-532 CWE Name: Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. Source: Splunk
Common Attack Pattern Enumeration and Classification (CAPEC)