CVE-2025-20227 Information

Description

In Splunk Enterprise versions below 9.4.1 9.3.3 9.2.5 and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107 9.2.2406.112 9.2.2403.115 9.1.2312.208 and 9.1.2308.214 a low-privileged user that does not hold the dmin\ or \power\ Splunk roles could bypass the external content warning modal dialog box in Dashboard Studio dashboards which could lead to an information disclosure.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Reference

https://advisory.splunk.com/advisories/SVD-2025-0306

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

4.3

Share on: