CVE-2025-20227

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could bypass the external content warning modal dialog box in Dashboard Studio dashboards which could lead to an information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ciscoCNA
4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
VendorProductVersion
splunksplunk
9.1.0 ≤
𝑥
< 9.1.8
splunksplunk
9.2.0 ≤
𝑥
< 9.2.4
splunksplunk
9.3.0 ≤
𝑥
< 9.3.3
splunksplunk
9.4.0
splunksplunk_cloud_platform
9.1.2308 ≤
𝑥
< 9.1.2308.214
splunksplunk_cloud_platform
9.1.2312 ≤
𝑥
< 9.1.2312.208
splunksplunk_cloud_platform
9.2.2403 ≤
𝑥
< 9.2.2403.115
splunksplunk_cloud_platform
9.2.2406.100 ≤
𝑥
< 9.2.2406.113
splunksplunk_cloud_platform
9.3.2408.100 ≤
𝑥
< 9.3.2408.107
𝑥
= Vulnerable software versions