CVE-2025-20321 Information
Description
In Splunk Enterprise versions below 9.4.3 9.3.5 9.2.7 and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.104 9.3.2408.114 and 9.2.2406.119 an unauthenticated attacker can send a specially-crafted SPL search that could change the membership state in a Splunk Search Head Cluster (SHC) through a Cross-Site Request Forgery (CSRF) potentially leading to the removal of the captain or a member of the SHC.
The vulnerability requires the attacker to phish the administrator-level victim by tricking them into initiating a request within their browser. The attacker should not be able to exploit the vulnerability at will.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Reference
https://advisory.splunk.com/advisories/SVD-2025-0704
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
6.5
Related CNNVD
CNNVD-202507-753 (Published: 2025-07-07)
Share on: