8
CVE-2025-20229
- EPSS 0.41%
- Veröffentlicht 26.03.2025 22:05:09
- Zuletzt bearbeitet 21.07.2025 20:49:49
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) through a file upload to the "$SPLUNK_HOME/var/run/splunk/apptemp" directory due to missing authorization checks.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Splunk ≫ Splunk Cloud Platform Version >= 9.1.2312 < 9.1.2312.208
Splunk ≫ Splunk Cloud Platform Version >= 9.2.2403 < 9.2.2403.114
Splunk ≫ Splunk Cloud Platform Version >= 9.2.2406.100 < 9.2.2406.108
Splunk ≫ Splunk Cloud Platform Version >= 9.3.2408.100 < 9.3.2408.104
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.41% | 0.607 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
psirt@cisco.com | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.