CVE-2025-0367
Regular Expression Denial of Service (ReDoS) in Splunk Supporting Add-on for Active Directory (SA-ldapsearch)
Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.005
40.8th percentile
Discovered by
Not disclosed
Published
Jan 30, 2025
Assigned by splunk
Description
In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.
Weakness: CWE-1333
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Apps & Add-ons | SIEM & Log Management | affected-vendor |
Vendor-reported products (1)
- Splunk · Splunk Supporting Add-on for Active Directory
Credit
Kyle Bambrick, Splunk