CVE-2025-20233

Incorrect permissions set by the “chmod“ and “makedirs“ Python functions in Splunk App for Lookup File Editing

Severity
Low 2.5
CVSS 3.1
Exploited
Not listed
EPSS
0.001
1.8th percentile
Discovered by
Not disclosed
Published
Mar 26, 2025
Assigned by cisco

Description

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.

Weakness: CWE-732

Affected products

Vendor Product Category Matched by
Cisco Splunk Apps & Add-ons SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Splunk · Splunk App for Lookup File Editing

Credit

Kyle Bambrick, Splunk

Something wrong here?