CVE 4.3 MEDIUM

Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app_CVE-2025-20383

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.

Basic Information

ID CVE-2025-20383
Source cisco
Published Dec 3, 2025 at 17:00
Modified Dec 3, 2025 at 21:33

Affected Product

Vendor Splunk
Product Splunk Enterprise
Version 10.0
Affected Versions Splunk Splunk Enterprise 10.0
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Cloud Platform 10.1.2507
Splunk Splunk Cloud Platform 10.0.2503
Splunk Splunk Cloud Platform 9.3.2411
Splunk Splunk Secure Gateway 3.9
Splunk Splunk Secure Gateway 3.8
Splunk Splunk Secure Gateway 3.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.