CyberRota Analysis
AI-GeneratedIn Splunk SOAR versions prior to 8.6.0, the lack of proper validation in the connectivity check REST API allows users with the "Administrator" role to exploit a Server-Side Request Forgery (SSRF) vulnerability, enabling them to initiate outbound network connections to arbitrary destinations. This could lead to unauthorized access to internal systems and data leakage. Organizations using affected versions of Splunk SOAR should prioritize upgrading to mitigate potential security risks.
Original NVD Description
In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary destinations and determine whether internal hosts and ports are reachable. The Server-Side Request Forgery (SSRF) is possible because the connectivity check REST API does not sufficiently validate the destination before Splunk SOAR connects to it. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)