Server-Side Request Forgery in Splunk Enterprise and Cloud Platform
CVE-2025-20371
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 1 October 2025
What is CVE-2025-20371?
In specific versions of Splunk Enterprise and Splunk Cloud Platform, an unauthenticated attacker can exploit a blind server-side request forgery (SSRF) vulnerability. This allows the attacker to make REST API calls with the authority of a high-privileged user, potentially exposing sensitive data and increasing security risks. It is crucial for users of affected Splunk products to apply appropriate security measures and updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Splunk Cloud Platform 9.3.2411 < 9.3.2411.109
Splunk Cloud Platform 9.3.2408 < 9.3.2408.119
Splunk Cloud Platform 9.2.2406 < 9.2.2406.122
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved