Description
In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files due to improper validation at the /en-US/static/ web endpoint. This may allow them to poison, forge, or obfuscate sensitive log data through specially crafted HTTP requests, potentially impacting log integrity and detection capabilities.
INFO
Published Date :
2025-12-03T17:00:34.212Z
Last Modified :
2025-12-03T21:32:24.714Z
Source :
cisco
AFFECTED PRODUCTS
The following products are affected by CVE-2025-20384 vulnerability.
| Vendors | Products |
|---|---|
| Splunk |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-20384.
| URL | Resource |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-1203 |
|