CVE-2025-20369

MEDIUM WAF: High
CVSS 6.5 Published: 2025-10-01
CWE-611

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of service (DoS) attacks.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
splunksplunk9.2.0 - 9.2.8
splunksplunk9.3.0 - 9.3.6
splunksplunk9.4.0 - 9.4.4
splunksplunk_cloud_platform9.2.2406 - 9.2.2406.123
splunksplunk_cloud_platform9.3.2408 - 9.3.2408.118
splunksplunk_cloud_platform9.3.2411 - 9.3.2411.108

References

Back to CVE Database