Back to Database
Status published
High
CVE-2023-46230
Sensitive Information Disclosure to Internal Log Files in Splunk Add-on Builder
Vulnerability Description
In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-46230
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Vikram Ashtaputre, Splunk
More from Splunk
View All →CVE-2025-22621
Privilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAR
Medium
6.4
CVE-2025-20389
Improper Input Validation in "label" column field in Splunk Secure Gateway App
Medium
4.3
CVE-2025-20388
Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise
Low
2.7
CVE-2025-20387
Incorrect permissions assignment on Splunk Universal Forwarder for Windows during new installation or upgrade
High
8
CVE-2025-20386
Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade
High
8
Affected Vendor
Splunk
View all reports →Affected Software
Splunk Add-on Builder
Vulnerable Versions:
-
Timeline
Official Publish:
January 30th, 2024
Last Modified:
May 30th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L