CVE-2025-20382: URL validation bypass through Views Dashboard in Splunk Enterprise
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a views dashboard with a custom background using the data:image/png;base64 protocol that could potentially lead to an unvalidated redirect. This behavior circumvents the Splunk external URL warning mechanism by using a specially crafted URL, allowing for a redirection to an external malicious site. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20382?
CVE-2025-20382 is classified as a low-severity vulnerability affecting certain Splunk versions.
How do I fix CVE-2025-20382?
To fix CVE-2025-20382, upgrade to Splunk Enterprise version 10.0.2 or later and Splunk Cloud Platform version 10.1.2507.10 or later.
Who is affected by CVE-2025-20382?
CVE-2025-20382 affects low-privileged users in Splunk Enterprise and Splunk Cloud Platform versions below the specified thresholds.
What can a low-privileged user do in CVE-2025-20382?
A low-privileged user can create a views dashboard with a custom background, potentially leading to unauthorized content.
When was CVE-2025-20382 reported?
CVE-2025-20382 was reported in 2025, with various affected Splunk versions outlined in the vulnerability description.