Improper access control in Splunk Enterprise and Splunk Secure Gateway - CVE-2025-20230

 

Improper access control in Splunk Enterprise and Splunk Secure Gateway - CVE-2025-20230

Published: March 26, 2025


Vulnerability identifier: #VU106069
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20230
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and edit or delete other user data in App Key Value Store (KVStore) collections that the Splunk Secure Gateway app created.


Affected software

Splunk Enterprise
Splunk Secure Gateway

How to mitigate CVE-2025-20230

Install updates from vendor's website.

Splunk Enterprise - addressed in versions 9.1.8, 9.2.5, 9.3.3, 9.4.1
Splunk Secure Gateway - addressed in versions 3.7.23, 3.8.38

External References

Related Security Bulletins