Cross-Site Request Forgery Vulnerability in Splunk Enterprise and Splunk Cloud Platform
CVE-2025-20322
4.3MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 7 July 2025
What is CVE-2025-20322?
In earlier versions of Splunk Enterprise and Splunk Cloud Platform, an unauthenticated attacker can exploit a cross-site request forgery vulnerability by crafting a malicious SPL search command. This may result in an unexpected rolling restart of the Search Head Cluster, leading to potential denial of service conditions. The attack requires social engineering techniques to trick an administrator into executing the malicious request in their browser, making it contingent on user interaction.
Affected Version(s)
Splunk Enterprise 9.4 < 9.4.3
Splunk Enterprise 9.3 < 9.3.5
Splunk Enterprise 9.2 < 9.2.7
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anton (therceman)