CVE-2025-20371: Unauthenticated Blind Server Side Request Forgery (SSRF) in Splunk Enterprise
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an authenticated high-privileged user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20371?
CVE-2025-20371 is classified as a high severity vulnerability due to the potential for unauthenticated SSRF attacks that could compromise sensitive information.
How do I fix CVE-2025-20371?
To remediate CVE-2025-20371, update Splunk Enterprise to version 10.0.1 or later, and for Splunk Cloud Platform update to version 9.3.2411.109 or later.
What versions are affected by CVE-2025-20371?
CVE-2025-20371 affects Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, 9.2.8 and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119, 9.2.2406.122.
What type of attack does CVE-2025-20371 facilitate?
CVE-2025-20371 facilitates blind server-side request forgery (SSRF) attacks that can allow unauthorized access to internal services.
Who can exploit CVE-2025-20371?
CVE-2025-20371 can be exploited by unauthenticated attackers, making it particularly concerning for organizations using affected versions.