← Back

CVE-2025-20383

nvd nist
Published: Dec 3, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: psirt@cisco.com (Secondary)

Description

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.

Affected (10)

3 products
Splunk
Splunk Cloud Platform
Splunk Secure Gateway
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 10.0.0 to 10.0.2
From 9.2.0 to 9.2.10
From 9.3.0 to 9.3.8
From 9.4.0 to 9.4.6
Splunk
From 10.0.2503 to 10.0.2503.8
From 10.1.2507 to 10.1.2507.6
From 9.3.2411 to 9.3.2411.120
Splunk
From 3.7.0 to 3.7.28
From 3.8.0 to 3.8.58
From 3.9.0 to 3.9.10

References (1)

Source: psirt@cisco.com
Vendor Advisory

Timeline

No history available yet.