Improper access control in Splunk Enterprise and Splunk Secure Gateway - CVE-2025-20230
Published: March 26, 2025
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and edit or delete other user data in App Key Value Store (KVStore) collections that the Splunk Secure Gateway app created.
Affected software
Splunk Secure Gateway
How to mitigate CVE-2025-20230
Splunk Secure Gateway - addressed in versions 3.7.23, 3.8.38