← Back

CVE-2025-20227

nvd nist
Published: Mar 26, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could bypass the external content warning modal dialog box in Dashboard Studio dashboards which could lead to an information disclosure.

Affected (9)

2 products
Splunk
Splunk Cloud Platform
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 9.1.0 to 9.1.8
From 9.2.0 to 9.2.4
From 9.3.0 to 9.3.3
Version 9.4.0
Splunk
From 9.1.2308 to 9.1.2308.214
From 9.1.2312 to 9.1.2312.208
From 9.2.2403 to 9.2.2403.115
From 9.2.2406.100 to 9.2.2406.113
From 9.3.2408.100 to 9.3.2408.107

References (1)

Source: psirt@cisco.com
Vendor Advisory

Timeline

No history available yet.