CyberRota Analysis
AI-GeneratedVersions prior to 2.3.8 of the AD LDAP app for Splunk SOAR are vulnerable, allowing users with action execution permissions to inadvertently log sensitive credentials in plaintext to a persistent debug file. This exposure could lead to unauthorized access and data breaches. Organizations utilizing this app should prioritize upgrading to mitigate the risk of credential leakage.
Original NVD Description
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).