Unvalidated Redirect Vulnerability in Splunk Enterprise and Cloud Platform
CVE-2025-20382
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 3 December 2025
What is CVE-2025-20382?
In various versions of Splunk Enterprise and Splunk Cloud Platform, a low-privileged user can exploit a flaw that allows them to create a views dashboard with a custom background using base64 encoded data. This can lead to an unvalidated redirect, evading the Splunk external URL warning system. The attack requires phishing tactics to convince an authenticated user to request the crafted URL, potentially directing them to a malicious site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Splunk Cloud Platform 10.1.2507 < 10.1.2507.10
Splunk Cloud Platform 10.0.2503 < 10.0.2503.8
Splunk Cloud Platform 9.3.2411 < 9.3.2411.120
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved