Information Disclosure in Splunk Enterprise and Splunk Secure Gateway App
CVE-2025-20383

4.3MEDIUM

What is CVE-2025-20383?

In specific versions of Splunk Enterprise and the Splunk Secure Gateway app, low-privileged users can receive mobile push notifications containing sensitive report and alert details. This occurs despite the users lacking necessary permissions to access the actual report or alert, potentially exposing confidential data inadvertently.

Affected Version(s)

Splunk Cloud Platform 10.1.2507 < 10.1.2507.6

Splunk Cloud Platform 10.0.2503 < 10.0.2503.8

Splunk Cloud Platform 9.3.2411 < 9.3.2411.120

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anton (therceman)
.