CVE-2025-20383

Published Dec 3, 2025

Last updated 5 months ago

Overview

Description
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.
Source
psirt@cisco.com
NVD status
Analyzed
Products
splunk, splunk_cloud_platform, splunk_secure_gateway

Risk scores

CVSS 3.1

Type
Primary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

psirt@cisco.com
CWE-200
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.