Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-20383


In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.


Published

2025-12-03T17:15:50.567

Last Modified

2025-12-05T18:30:13.090

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application splunk splunk < 9.2.10 Yes
Application splunk splunk < 9.3.8 Yes
Application splunk splunk < 9.4.6 Yes
Application splunk splunk < 10.0.2 Yes
Application splunk splunk_cloud_platform < 9.3.2411.120 Yes
Application splunk splunk_cloud_platform < 10.0.2503.8 Yes
Application splunk splunk_cloud_platform < 10.1.2507.6 Yes
Application splunk splunk_secure_gateway < 3.7.28 Yes
Application splunk splunk_secure_gateway < 3.8.58 Yes
Application splunk splunk_secure_gateway < 3.9.10 Yes

References