CVE-2025-20232 Details
Description
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.2312.208 and 9.1.2308.212, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on the “/app/search/search“ endpoint through its “s“ parameter. <br>The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.
A vulnerability exists in Splunk Enterprise versions prior to 9.3.3, 9.2.5, and 9.1.8, as well as in Splunk Cloud Platform versions prior to 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.2312.208, and 9.1.2308.212. This vulnerability allows low-privileged users, who do not have 'admin' or 'power' roles, to bypass SPL safeguards for risky commands on the '/app/search/search' endpoint. By using the 's' parameter, these users can execute saved searches with risky commands, leveraging the permissions of higher-privileged users. The exploitation requires phishing the victim to initiate the request through their browser, as the authenticated user cannot exploit the vulnerability independently.
Users of Splunk Enterprise should upgrade to versions 9.4.0, 9.3.3, 9.2.5, or 9.1.8. For Splunk Cloud Platform users, no action is needed as Splunk is actively monitoring and patching instances. Additionally, turning off Splunk Web can mitigate the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-0304 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| splunk splunk | >= 9.1.0, < 9.1.8 >= 9.2.0, < 9.2.5 >= 9.3.0, < 9.3.3 |
CPE
Remediation
| |
| splunk splunk cloud platform | >= 9.1.2308, < 9.1.2308.212 >= 9.1.2312.100, < 9.1.2312.208 >= 9.2.2403.100, < 9.2.2403.113 >= 9.2.2406.100, < 9.2.2406.108 >= 9.3.2408.100, < 9.3.2408.103 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2025 | Initial Analysis | [email protected] |
| Mar 26, 2025 | New CVE Received | [email protected] |