Cross-Site Request Forgery Vulnerability in Splunk Enterprise and Splunk Cloud Platform
CVE-2025-20322

4.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
7 July 2025

What is CVE-2025-20322?

In earlier versions of Splunk Enterprise and Splunk Cloud Platform, an unauthenticated attacker can exploit a cross-site request forgery vulnerability by crafting a malicious SPL search command. This may result in an unexpected rolling restart of the Search Head Cluster, leading to potential denial of service conditions. The attack requires social engineering techniques to trick an administrator into executing the malicious request in their browser, making it contingent on user interaction.

Affected Version(s)

Splunk Enterprise 9.4 < 9.4.3

Splunk Enterprise 9.3 < 9.3.5

Splunk Enterprise 9.2 < 9.2.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anton (therceman)
.