In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could bypass the external content warning modal dialog box in Dashboard Studio dashboards which could lead to an information disclosure.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-0306 |     | 
History
                    Mon, 21 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Splunk Splunk splunk Splunk splunk Cloud Platform | |
| CPEs | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* cpe:2.3:a:splunk:splunk:9.4.0:*:*:*:enterprise:*:*:* cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* | |
| Vendors & Products | Splunk Splunk splunk Splunk splunk Cloud Platform | 
Thu, 27 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 26 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could bypass the external content warning modal dialog box in Dashboard Studio dashboards which could lead to an information disclosure. | |
| Title | Information Disclosure through external content warning modal dialog box bypass in Splunk Enterprise Dashboard Studio | |
| Weaknesses | CWE-20 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cisco
Published: 2025-03-26T22:03:50.424Z
Updated: 2025-03-27T13:50:15.585Z
Reserved: 2024-10-10T19:15:13.236Z
Link: CVE-2025-20227
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-03-27T13:50:11.927Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-03-26T22:15:14.637
Modified: 2025-07-21T20:51:45.463
Link: CVE-2025-20227
 Redhat
                        Redhat
                    No data.