HomeSecuritySplunk Enterprise: Vulnerabilities allow JavaScript code execution

Splunk Enterprise: Vulnerabilities allow JavaScript code execution

Splunk has released updates for multiple vulnerabilities in its Enterprise and Cloud Platform products , some of which could allow attackers to execute JavaScript code , gain access to sensitive information , or cause a denial-of-service (DoS).

Splunk Vulnerabilities

The notices, published on October 1, 2025, describe six security flaws, with severity ratings ranging from Moderate to High.

Splunk: Vulnerability Details

The most critical vulnerability is a Server-Side Request Forgery (SSRF) flaw, tracked as CVE-2025-20371 (with a CVSS score of 7.5/10). This vulnerability could allow an unauthenticated attacker to cause a blind SSRF , potentially allowing them to execute REST API calls on behalf of an authorized user with elevated privileges. Successful exploitation requires the enableSplunkWebClientNetloc setting to be enabled and may involve phishing to have the victim initiate a request from their browser.

See also: Hackers exploit Milesight routers to send phishing SMS

Splunk Enterprise: Vulnerabilities allow JavaScript code execution

Two vulnerabilities involve JavaScript code execution, a form of cross-site scripting (XSS):

CVE-2025-20367 (CVSS: 5.7): A low-privileged user can craft a malicious payload via the dataset.command parameter of a specific endpoint, leading to JavaScript code execution in a browser .

CVE-2025-20368 (CVSS: 5.7): Similarly, a low-privileged user can inject a malicious payload into the error messages and job inspection details of a saved search, resulting in code execution.

Another significant flaw, CVE-2025-20366 (CVSS: 6.5), allows information disclosure. In this scenario, a low-privileged user, without 'admin' or 'power' roles, could gain access to the results of an administrative search job running in the background. If the attacker correctly guesses the job's unique Search ID (SID), they could retrieve potentially sensitive search results.

See also: 48+ Cisco Firewalls vulnerable to active zero-day vulnerability

The security update also addresses two moderate severity vulnerabilities that could impact system availability and integrity:

CVE-2025-20370 (CVSS: 4.9): A user with the change_authentication capability can send multiple LDAP bind requests to an internal endpoint, causing high CPU usage and a possible DoS condition requiring a reboot.

CVE-2025-20369 (CVSS: 4.6): A low-privileged user can perform XML External Entity (XXE) injection via the dashboard tab label field, which could also lead to a DoS attack.

The vulnerabilities affect multiple versions of Splunk Enterprise and Splunk Cloud Platform. Affected versions of Splunk Enterprise include those below 9.4.4, 9.3.6, and 9.2.8. Some also affect version 10.0.0.

See also: Vulnerabilities in Google Gemini allow data extraction

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Splunk Enterprise: Vulnerabilities allow JavaScript code execution

Splunk has released updates and encourages customers to upgrade to the following or later versions:

CVE IDVulnerability TypeCVSS 3.1 ScoreAffected ProductAffected VersionsFixed Versions
CVE-2025-20366Information Disclosure6.5 (Medium)Splunk Enterprise9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.79.4.4 9.3.6 9.2.8
Splunk Cloud PlatformBelow 9.3.2411.111 Below 9.3.2408.119 Below 9.2.2406.1229.3.2411.111 9.3.2408.119 9.2.2406.122
CVE-2025-20367Cross-Site Scripting (XSS)5.7 (Medium)Splunk Enterprise9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.79.4.4 9.3.6 9.2.8
Splunk Cloud PlatformBelow 9.3.2411.109 Below 9.3.2408.119 Below 9.2.2406.1229.3.2411.109 9.3.2408.119 9.2.2406.122
CVE-2025-20368Cross-Site Scripting (XSS)5.7 (Medium)Splunk Enterprise9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.79.4.4 9.3.6 9.2.8
Splunk Cloud PlatformBelow 9.3.2411.108 Below 9.3.2408.118 Below 9.2.2406.1239.3.2411.108 9.3.2408.118 9.2.2406.123
CVE-2025-20369XXE Injection4.6 (Medium)Splunk Enterprise9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.79.4.4 9.3.6 9.2.8
Splunk Cloud PlatformBelow 9.3.2411.108 Below 9.3.2408.118 Below 9.2.2406.1239.3.2411.108 9.3.2408.118 9.2.2406.123
CVE-2025-20370Denial of Service (DoS)4.9 (Medium)Splunk Enterprise10.0.0 9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.710.0.1 9.4.4 9.3.6 9.2.8
Splunk Cloud PlatformBelow 9.3.2411.108 Below 9.3.2408.118 Below 9.2.2406.1239.3.2411.108 9.3.2408.118 9.2.2406.123
CVE-2025-20371Server-Side Request Forgery (SSRF)7.5 (High)Splunk Enterprise10.0.0 9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.710.0.1 9.4.4 9.3.6 9.2.8
Splunk Cloud PlatformBelow 9.3.2411.109 Below 9.3.2408.119 Below 9.2.2406.1229.3.2411.109 9.3.2408.119 9.2.2406.122

Splunk has confirmed that it is actively updating all Splunk Cloud Platform instances and will notify customers upon completion.

For users who cannot apply the updates immediately, there are several workarounds available. It is recommended to disable Splunk Web unless necessary. For the SSRF flaw (CVE-2025-20371), administrators can mitigate the risk by setting enableSplunkWebClientNetloc to false in the web.conf file.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS