CVE-2023-22943: Splunk Add-On Builder
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectly revert to using HTTP to connect after a failure to connect over HTTPS occurs.
Affected products
- Splunk Add-On Builder: from 4.1.0, before 4.1.2 (fixed in 4.1.2)
- Splunk Cloudconnect Software Development Kit: from 3.1.0, before 3.1.3 (fixed in 3.1.3)
Published 2023-02-14. Last modified 2026-06-17.