CVE-2025-20384

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files due to improper validation at the /en-US/static/ web endpoint. This may allow them to poison, forge, or obfuscate sensitive log data through specially crafted HTTP requests, potentially impacting log integrity and detection capabilities.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:10.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*

History

05 Dec 2025, 18:14

Type Values Removed Values Added
References () https://advisory.splunk.com/advisories/SVD-2025-1203 - () https://advisory.splunk.com/advisories/SVD-2025-1203 - Vendor Advisory
First Time Splunk splunk
Splunk
Splunk splunk Cloud Platform
CPE cpe:2.3:a:splunk:splunk:10.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*

03 Dec 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 17:15

Updated : 2025-12-05 18:14


NVD link : CVE-2025-20384

Mitre link : CVE-2025-20384

CVE.ORG link : CVE-2025-20384


JSON object : View

Products Affected

splunk

  • splunk_cloud_platform
  • splunk
CWE
CWE-117

Improper Output Neutralization for Logs