CVE-2025-20369

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/10/2025
Last modified:
08/10/2025

Description

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of service (DoS) attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* 9.2.0 (including) 9.2.8 (excluding)
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* 9.3.0 (including) 9.3.6 (excluding)
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* 9.4.0 (including) 9.4.4 (excluding)
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* 9.2.2406 (including) 9.2.2406.123 (excluding)
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* 9.3.2408 (including) 9.3.2408.118 (excluding)
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* 9.3.2411 (including) 9.3.2411.108 (excluding)


References to Advisories, Solutions, and Tools