CVE-2025-20228: Maintenance mode state change of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF) in Splunk Enterprise
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20228?
CVE-2025-20228 has a low severity rating due to the limited permissions needed for exploitation.
How do I fix CVE-2025-20228?
To fix CVE-2025-20228, upgrade Splunk Enterprise to version 9.3.3 or later, or Splunk Cloud Platform to version 9.2.2403.108 or later.
Who is affected by CVE-2025-20228?
CVE-2025-20228 affects low-privileged users in Splunk Enterprise and Splunk Cloud Platform versions below the specified updates.
What is the impact of CVE-2025-20228?
The impact of CVE-2025-20228 allows unauthorized users to change the maintenance mode state of the App Key Value Store.
Is there a workaround for CVE-2025-20228?
There is no official workaround for CVE-2025-20228; the best recommendation is to apply the necessary software updates.