« Volver al listado

CVE-2025-20382

Estado: AnalizadaMedia (5.4)—

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a views dashboard with a custom background using the `data:image/png;base64` protocol that could potentially lead to an unvalidated redirect. This behavior circumvents the Splunk external URL warning mechanism by using a specially crafted URL, allowing for a redirection to an external malicious site. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-20382",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-20382",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-03T21:28:22.162687Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@cisco.com",
      "affectedData": [
        {
          "vendor": "Splunk",
          "product": "Splunk Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "10.0",
              "lessThan": "10.0.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.4",
              "lessThan": "9.4.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.3",
              "lessThan": "9.3.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.2",
              "lessThan": "9.2.10",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Splunk",
          "product": "Splunk Cloud Platform",
          "versions": [
            {
              "status": "affected",
              "version": "10.1.2507",
              "lessThan": "10.1.2507.10",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.0.2503",
              "lessThan": "10.0.2503.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.3.2411",
              "lessThan": "9.3.2411.120",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-03T17:15:50.380",
  "references": [
    {
      "url": "https://advisory.splunk.com/advisories/SVD-2025-1201",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@cisco.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could create a views dashboard with a custom background using the `data:image/png;base64` protocol that could potentially lead to an unvalidated redirect. This behavior circumvents the Splunk external URL warning mechanism by using a specially crafted URL, allowing for a redirection to an external malicious site. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will."
    },
    {
      "lang": "es",
      "value": "En las versiones de Splunk Enterprise anteriores a 10.0.2, 9.4.6, 9.3.8 y 9.2.10, y en las versiones de Splunk Cloud Platform anteriores a 10.1.2507.10, 10.0.2503.8 y 9.3.2411.120, un usuario con privilegios bajos que no posee los roles de Splunk 'admin' o 'power' podría crear un panel de vistas con un fondo personalizado utilizando el protocolo 'data:image/png;base64' que podría conducir potencialmente a una redirección no validada. Este comportamiento elude el mecanismo de advertencia de URL externa de Splunk mediante el uso de una URL especialmente diseñada, permitiendo una redirección a un sitio malicioso externo. La vulnerabilidad requiere que el atacante realice phishing a la víctima engañándolos para que inicien una solicitud dentro de su navegador. El usuario autenticado no debería poder explotar la vulnerabilidad a voluntad."
    }
  ],
  "lastModified": "2026-06-17T08:41:39.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE8BF109-2B9C-4C50-AC9F-10A45456FD75",
              "versionEndExcluding": "9.2.10",
              "versionStartIncluding": "9.2.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05D6973D-D965-42D3-8320-AF4A4B424E6C",
              "versionEndExcluding": "9.3.8",
              "versionStartIncluding": "9.3.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8571F470-6AE1-4737-B1FA-49121E426AF2",
              "versionEndExcluding": "9.4.6",
              "versionStartIncluding": "9.4.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4413D4BE-F225-4C28-B401-EB46D8F34160",
              "versionEndExcluding": "10.0.2",
              "versionStartIncluding": "10.0.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6CA3000-9C26-45B9-A2A2-C22F3F4246BC",
              "versionEndExcluding": "9.3.2411.120",
              "versionStartIncluding": "9.3.2411"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D269788F-7244-4307-B551-C1B943EF2BB9",
              "versionEndExcluding": "10.0.2503.8",
              "versionStartIncluding": "10.0.2503"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4124F3F-581D-429F-AB92-4C7515AA16A5",
              "versionEndExcluding": "10.1.2507.10",
              "versionStartIncluding": "10.1.2507"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@cisco.com"
}