PT-2025-48954 · Splunk · Splunk Cloud Platform+1

Anton

·

Published

2025-12-03

·

Updated

2025-12-05

·

CVE-2025-20382

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.0.2, 9.4.6, 9.3.8, and 9.2.10 Splunk Cloud Platform versions prior to 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120
Description A user with limited privileges, lacking administrator or power roles, can create a views dashboard with a custom background image using the data:image/png;base64 protocol. This can lead to an unvalidated redirect, bypassing Splunk’s external URL warning mechanism and potentially redirecting a user to a malicious website. Exploitation requires an attacker to phish a victim into initiating a request within their browser. The authenticated user cannot independently exploit this issue. The vulnerability involves crafting a URL to achieve the redirection.
Recommendations Update Splunk Enterprise to version 10.0.2 or later. Update Splunk Enterprise to version 9.4.6 or later. Update Splunk Enterprise to version 9.3.8 or later. Update Splunk Enterprise to version 9.2.10 or later. Update Splunk Cloud Platform to version 10.1.2507.10 or later. Update Splunk Cloud Platform to version 10.0.2503.8 or later. Update Splunk Cloud Platform to version 9.3.2411.120 or later.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2025-16294
CVE-2025-20382

Affected Products

Splunk Cloud Platform
Splunk Enterprise