CVE-2023-46230: Sensitive Information Disclosure to Internal Log Files in Splunk Add-on Builder
Published Jan 30, 2024
·Updated
In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.
Affected Software
1 affected component
splunk Add-on Builder<4.1.4
Event History
Jan 30, 2024
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46230?
CVE-2023-46230 has a moderate severity due to the exposure of sensitive information through internal log files.
2
How do I fix CVE-2023-46230?
To fix CVE-2023-46230, upgrade to Splunk Add-on Builder version 4.1.4 or later.
3
What versions are affected by CVE-2023-46230?
CVE-2023-46230 affects all versions of Splunk Add-on Builder below 4.1.4.
4
What kind of information is exposed in CVE-2023-46230?
CVE-2023-46230 exposes sensitive information written to internal log files, which can be exploited by unauthorized users.
5
Is there a workaround for CVE-2023-46230?
There is no official workaround for CVE-2023-46230; upgrading to the fixed version is the recommended action.