#VU116648 Blind Server-Side Request Forgery (SSRF) in Splunk Enterprise - CVE-2025-20371
Published: October 7, 2025
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim into initiating a request from their browser and force the application to initiate REST API calls on behalf of an authenticated high-privileged user.
Successful exploitation of this vulnerability requires that the "enableSplunkWebClientNetloc" setting in the web.conf configuration file to have a value of "true".