CVE-2025-20227

Severity
4.3MEDIUM
EPSS
0.2%
top 55.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 26
Latest updateMar 27

Description

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could bypass the external content warning modal dialog box in Dashboard Studio dashboards which could lead to an information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5splunk/splunk_cloud_platform9.3.24089.3.2408.107+4
NVDsplunk/splunk_cloud_platform9.1.23089.1.2308.214+4
CVEListV5splunk/splunk_enterprise9.49.4.1+3
NVDsplunk/splunk9.1.09.1.8+3

🔴Vulnerability Details

2
GHSA
GHSA-66v8-2jrc-g3f2: In Splunk Enterprise versions below 92025-03-27
CVEList
Information Disclosure through external content warning modal dialog box bypass in Splunk Enterprise Dashboard Studio2025-03-26
CVE-2025-20227 (MEDIUM CVSS 4.3) | In Splunk Enterprise versions below | cvebase.io