CVE-2025-20227
Information Disclosure through external content warning modal dialog box bypass in Splunk Enterprise Dashboard Studio
Severity
Medium 4.3
CVSS 3.1
Exploited
Not listed
EPSS
0.004
32.3th percentile
Discovered by
Not disclosed
Published
Mar 26, 2025
Assigned by cisco
Description
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could bypass the external content warning modal dialog box in Dashboard Studio dashboards which could lead to an information disclosure.
Weakness: CWE-20
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (2)
- Splunk · Splunk Enterprise
- Splunk · Splunk Cloud Platform
Credit
Taihei Shimamine