CyberzSOC

Publication detail
← Back to advisories & guidance

2025-013: Remote Code Execution Vulnerability in Splunk ↗ source

March 27, 2025 CERT-EU Advisory

Summary

The vulnerability CVE-2025-20229 , with a CVSS Score of 8.0, stems from missing authorisation checks in the file upload process to the $SPLUNK_HOME/var/run/splunk/apptemp directory. It allows low-privileged users to execute arbitrary code remotely by uploading malicious files to this specific directory on the server. The following products and versions are affected: from 9.2.2406 to 9.2.2406.107 and from 9.3.2408 to 9.3.2408.103 CERT-EU recommends upgrading affected server to the latest version as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-20229 8.0 High Splunk Splunk Enterprise In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.