2.7

CVSS3.1

CVE-2025-20388 - Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.7, and 9.3.2411.116, a user who holds a role that contains the high privilege capability `change_authentication` could enumerate internal IP addresses and network po…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 5:11 p.m.

4.3

CVSS3.1

CVE-2025-20389 - Improper Input Validation in "label" column field in Splunk Secure Gateway App

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the `lab…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 5:05 p.m.

8

CVSS3.1

CVE-2025-20387 - Incorrect permissions assignment on Splunk Universal Forwarder for Windows during new installation …

In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory. This lets non-administrator users on th…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

4.3

CVSS3.1

CVE-2025-20383 - Improper access control through push notifications for reports and alerts in Splunk Secure Gateway …

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive no…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 6:30 p.m.

5.3

CVSS3.1

CVE-2025-20384 - Unauthenticated Log Injection in Splunk Enterprise

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files due to improper valid…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 6:14 p.m.

8

CVSS3.1

CVE-2025-20386 - Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade

In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets non-administrator users on the machine a…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

2.4

CVSS3.1

CVE-2025-20385 - Stored Cross-Site scripting (XSS) through Anchor Tag "href" in Navigation Bar Collections in Splunk…

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117, a user who holds a role with a high privilege capability `admin_all_objects` could craft a malicious payload through the href attribute of an an…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 6:13 p.m.

5.4

CVSS3.1

CVE-2025-20381 - SPL commands allowlist controls bypass in Splunk MCP Server app through "run_splunk_query" MCP tool

In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command allowlist controls in MCP by embedding SPL commands as sub-searches, leading to unauthorized actions beyond the intended MCP restrictions.

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

3.5

CVSS3.1

CVE-2025-20382 - URL validation bypass through Views Dashboard in Splunk Enterprise

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a views dashboard with a custom background using the …

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 6:33 p.m.

7.5

CVSS3.1

CVE-2024-3884 - Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows…

πŸ“… Published: Dec. 3, 2025, 4:50 p.m. πŸ”„ Last Modified: April 1, 2026, 1:32 p.m.
Total resulsts: 343975
Page 2318 of 34,398
Β« previous page Β» next page
Filters