CVE-2025-20297: Reflected Cross-Site Scripting (XSS) on Splunk Enterprise through dashboard PDF generation component
In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the pdfgen/render REST endpoint that could result in execution of unauthorized JavaScript code in the browser of a user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20297?
CVE-2025-20297 is classified as a low-severity vulnerability affecting specific versions of Splunk Enterprise and Splunk Cloud Platform.
How do I fix CVE-2025-20297?
To resolve CVE-2025-20297, users should upgrade their Splunk Enterprise to version 9.4.2 or higher, and Splunk Cloud Platform to version 9.3.2411.102 or higher.
Who is affected by CVE-2025-20297?
CVE-2025-20297 affects low-privileged users without 'admin' or 'power' roles in specified versions of Splunk software.
What are the affected versions listed in CVE-2025-20297?
The affected versions in CVE-2025-20297 include Splunk Enterprise versions below 9.4.2, 9.3.4, and 9.2.6, as well as Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111, and 9.2.2406.118.
What type of attack is possible due to CVE-2025-20297?
CVE-2025-20297 allows low-privileged users to craft a malicious payload through the pdfgen/render functionality.