CVE-2025-20322 Information
Description
In Splunk Enterprise versions below 9.4.3 9.3.5 9.2.7 and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.104 9.3.2408.113 and 9.2.2406.119 an unauthenticated attacker could send a specially-crafted SPL search command that could trigger a rolling restart in the Search Head Cluster through a Cross-Site Request Forgery (CSRF) potentially leading to a denial of service (DoS).
The vulnerability requires the attacker to phish the administrator-level victim by tricking them into initiating a request within their browser. The attacker should not be able to exploit the vulnerability at will.
See How rolling restart works for more information.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Reference
https://advisory.splunk.com/advisories/SVD-2025-0705
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
4.3
Related CNNVD
CNNVD-202507-757 (Published: 2025-07-07)
Share on: