CVE-2025-20230

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 284

Summary

CVE-2025-20230 is a vulnerability affecting Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, as well as versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform. It allows a low-privileged user, who does not possess the "admin" or "power" roles, to edit and delete other users' data in App Key Value Store (KVStore) collections created by the Splunk Secure Gateway app. This occurs due to insufficient access control and incorrect ownership of the data in these KVStore collections, with the `nobody` user being the default owner.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share