CVE-2025-20230

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could edit and delete other user data in App Key Value Store (KVStore) collections that the Splunk Secure Gateway app created. This is due to missing access control and incorrect ownership of the data in those KVStore collections.<br><br>In the affected versions, the `nobody` user owned the data in the KVStore collections. This meant that there was no specific owner assigned to the data in those collections.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*

History

01 Aug 2025, 18:01

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Splunk
Splunk splunk Secure Gateway
Splunk splunk
CPE cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
References () https://advisory.splunk.com/advisories/SVD-2025-0307 - () https://advisory.splunk.com/advisories/SVD-2025-0307 - Vendor Advisory
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 6.5

26 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-26 23:15

Updated : 2025-08-01 18:01


NVD link : CVE-2025-20230

Mitre link : CVE-2025-20230


JSON object : View

Products Affected

splunk

  • splunk
  • splunk_secure_gateway
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control