PT-2025-48955 · Splunk · Splunk Secure Gateway App+1

Anton

·

Published

2025-12-03

·

Updated

2025-12-05

·

CVE-2025-20383

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.0.2 Splunk Enterprise versions 9.2.10 through 9.4.6 Splunk Enterprise versions 9.3.8 Splunk Secure Gateway app versions below 3.7.28 Splunk Secure Gateway app versions 3.8.58 and below Splunk Secure Gateway app versions 3.9.10
Description A user with limited privileges, lacking 'admin' or 'power' roles, who is subscribed to mobile push notifications may receive notifications revealing the title and description of reports or alerts they are not authorized to view. This occurs in Splunk Enterprise and the Splunk Secure Gateway app within the Splunk Cloud Platform.
Recommendations Update Splunk Enterprise to version 10.0.2 or later. Update Splunk Enterprise to version 9.4.6 or later. Update Splunk Enterprise to version 9.3.8 or later. Update Splunk Enterprise to version 9.2.10 or later. Update Splunk Secure Gateway app to version 3.7.28 or later. Update Splunk Secure Gateway app to version 3.8.58 or later. Update Splunk Secure Gateway app to version 3.9.10 or later.

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-16299
CVE-2025-20383

Affected Products

Splunk Enterprise
Splunk Secure Gateway App