3.1
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Description
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121, an unauthenticated attacker could craft a malicious URL using the `return_to` parameter of the Splunk Web login endpoint. When an authenticated user visits the malicious URL, it could cause an unvalidated redirect to an external malicious site. To be successful, the attacker has to trick the victim into initiating a request from their browser. The unauthenticated attacker should not be able to exploit the vulnerability at will.
Basic Information
ID
CVE-2025-20378
Source
cisco
Published
Nov 12, 2025 at 17:22
Modified
Nov 12, 2025 at 21:04
Affected Product
Vendor
Splunk
Product
Splunk Enterprise
Version
10.0
Affected Versions
Splunk Splunk Enterprise 10.0
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Cloud Platform 10.0.2503
Splunk Splunk Cloud Platform 9.3.2411
Splunk Splunk Cloud Platform 9.3.2408
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Cloud Platform 10.0.2503
Splunk Splunk Cloud Platform 9.3.2411
Splunk Splunk Cloud Platform 9.3.2408