CVE-2025-20231
Splunk Enterprise vulnerability analysis and mitigation

Overview

A sensitive information disclosure vulnerability (CVE-2025-20231) was discovered in Splunk Enterprise and Splunk Secure Gateway app. The vulnerability affects Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform. This vulnerability was disclosed on March 26, 2025, and allows low-privileged users without admin or power roles to potentially access sensitive information through elevated search permissions (Splunk Advisory).

Technical details

The vulnerability stems from the Splunk Secure Gateway exposing user session and authorization tokens in clear text within the splunksecuregateway.log file when calling the /services/ssg/secrets REST endpoint. The vulnerability has been assigned a CVSS v3.1 base score of 7.1 (High) with the vector string CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H. It is categorized under CWE-532 (Insertion of Sensitive Information into Log File) (Splunk Advisory).

Impact

When successfully exploited, the vulnerability allows a low-privileged user to run searches using the permissions of a higher-privileged user, potentially leading to unauthorized access to sensitive information. The exposure of session and authorization tokens in clear text could enable attackers to impersonate users and retrieve sensitive information through elevated search permissions (Security Online).

Mitigation and workarounds

Splunk has released patches to address this vulnerability. Organizations should upgrade Splunk Enterprise to versions 9.4.1, 9.3.3, 9.2.5, and 9.1.8 or higher. For Splunk Cloud Platform, Splunk is actively monitoring and patching affected instances. As a temporary workaround, organizations can disable the Splunk Secure Gateway App if they don't use Splunk Mobile, Spacebridge, or Mission Control features (Splunk Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management