Cross-Site Request Forgery Vulnerability in Splunk Enterprise and Splunk Cloud Platform
CVE-2025-20322
4.3MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 7 July 2025
What is CVE-2025-20322?
In earlier versions of Splunk Enterprise and Splunk Cloud Platform, an unauthenticated attacker can exploit a cross-site request forgery vulnerability by crafting a malicious SPL search command. This may result in an unexpected rolling restart of the Search Head Cluster, leading to potential denial of service conditions. The attack requires social engineering techniques to trick an administrator into executing the malicious request in their browser, making it contingent on user interaction.
Affected Version(s)
Splunk Enterprise 9.4 < 9.4.3
Splunk Enterprise 9.3 < 9.3.5
Splunk Enterprise 9.2 < 9.2.7