Product
Splunk Connect for Kafka versions below 2.2.7 are vulnerable to credential theft through an unauthenticated REST API endpoint, allowing attackers to redirect HEC traffic to malicious servers.