First published: Tue Jan 30 2024(Updated: )
In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.
Credit: prodsec@splunk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Splunk Add-on Builder | <4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46230 has a moderate severity due to the exposure of sensitive information through internal log files.
To fix CVE-2023-46230, upgrade to Splunk Add-on Builder version 4.1.4 or later.
CVE-2023-46230 affects all versions of Splunk Add-on Builder below 4.1.4.
CVE-2023-46230 exposes sensitive information written to internal log files, which can be exploited by unauthorized users.
There is no official workaround for CVE-2023-46230; upgrading to the fixed version is the recommended action.