CVE-2025-20384

Source
https://cve.org/CVERecord?id=CVE-2025-20384
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-20384.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-20384
Published
2025-12-03T17:15:50.740Z
Modified
2026-03-12T17:38:56.778340Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files due to improper validation at the /en-US/static/ web endpoint. This may allow them to poison, forge, or obfuscate sensitive log data through specially crafted HTTP requests, potentially impacting log integrity and detection capabilities.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "9.2.0"
            },
            {
                "fixed": "9.2.10"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "9.3.0"
            },
            {
                "fixed": "9.3.8"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "9.4.0"
            },
            {
                "fixed": "9.4.6"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.0.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "9.3.2411"
            },
            {
                "fixed": "9.3.2411.117"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "10.0.2503"
            },
            {
                "fixed": "10.0.2503.6"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "10.1.2507"
            },
            {
                "fixed": "10.1.2507.4"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-20384.json"