CVE-2025-0367: Regular Expression Denial of Service (ReDoS) in Splunk Supporting Add-on for Active Directory (SA-ldapsearch)
In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0367?
CVE-2025-0367 is classified as a vulnerability that could lead to a Regular Expression Denial of Service (ReDoS) attack.
How do I fix CVE-2025-0367?
To fix CVE-2025-0367, upgrade the Splunk Supporting Add-on for Active Directory to version 3.1.1 or higher.
Which versions of the Splunk Supporting Add-on for Active Directory are affected by CVE-2025-0367?
Versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory are affected by CVE-2025-0367.
What can happen if I don't address CVE-2025-0367?
If CVE-2025-0367 is not addressed, an attacker could exploit the vulnerability to cause a denial of service by overwhelming the system.
Is there a public advisory for CVE-2025-0367?
Yes, there is a public advisory regarding CVE-2025-0367 available from Splunk.