Add On Builder
Vendor:
First CVE: Feb 14, 2023 · Active for 3 years
3
Total CVEs
More Total CVEs than 64% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Add On Builder over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 14, 2023
3 years ago
Most Recent CVE
Jan 30, 2024
907 days ago
CVE Severity & Scoring
Add On Builder3 CVEs
67%
33%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High2 (66.7%)
None1 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46231HIGH In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or ed | Jan 30, 2024 | 7.2 | 22 | NO | NO |
CVE-2023-22943MEDIUM In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectl | Feb 14, 2023 | 5.3 | 18 | NO | NO |
CVE-2023-46230MEDIUM In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files. | Jan 30, 2024 | 4.9 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (3 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (3 CVEs).
Media Mentions
Signals from CVEs in this product scope (3 CVEs).
Top CWEs
Versions
No cataloged versions.