In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an authenticated high-privileged user.
History

Thu, 02 Oct 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk
Splunk splunk Enterprise

Wed, 01 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an authenticated high-privileged user.
Title Unauthenticated Blind Server Side Request Forgery (SSRF) in Splunk Enterprise
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2025-10-02T03:55:47.543Z

Reserved: 2024-10-10T19:15:13.262Z

Link: CVE-2025-20371

cve-icon Vulnrichment

Updated: 2025-10-01T17:22:40.832Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-01T17:15:40.450

Modified: 2025-10-02T19:11:46.753

Link: CVE-2025-20371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-02T08:38:49Z