CVE-2025-20233

Incorrect permissions set by the “chmod“ and “makedirs“ Python functions in Splunk App for Lookup File Editing

Severity
Low 2.5
CVSS 3.1
Exploited
Not listed
EPSS
0.001
1.6th percentile
Discovered by
Not disclosed
Published
Mar 26, 2025
Assigned by cisco

Description

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.

Weakness: CWE-732

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • Splunk · Splunk App for Lookup File Editing

Credit

Kyle Bambrick, Splunk