CyberRota Analysis
AI-GeneratedVersions below 2.3.8 of the AD LDAP app for Splunk SOAR are vulnerable, allowing users with action execution permissions to inadvertently log sensitive Active Directory response data to a persistent debug log file. This could lead to unauthorized access to sensitive information, posing a risk to data confidentiality. Organizations using this app should prioritize upgrading to mitigate potential data exposure risks.
Original NVD Description
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).