In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files due to improper validation at the /en-US/static/ web endpoint. This may allow them to poison, forge, or obfuscate sensitive log data through specially crafted HTTP requests, potentially impacting log integrity and detection capabilities.
References
| Link | Resource |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-1203 |
Configurations
No configuration.
History
03 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-03 17:15
Updated : 2025-12-03 17:15
NVD link : CVE-2025-20384
Mitre link : CVE-2025-20384
CVE.ORG link : CVE-2025-20384
JSON object : View
Products Affected
No product.
CWE
CWE-117
Improper Output Neutralization for Logs
