Splunk: Updates close security gaps in several products

There are some high-risk security gaps in Splunk's security and monitoring software. Updates close them.

listen Print view
Hand taps the update button on the monitor

(Image: Erstellt mit KI in Bing Creator von heise online / dmk)

4 min. read

Splunk has reported a number of security vulnerabilities in several products. Updated software packages are available for download, which admins can use to plug these security leaks.

The most serious gap is apparently in Splunk Enterprise. It allows attackers from the network to infiltrate and execute malicious code. Apparently a login is required, but no elevated rights of the roles "admin" or "power" (CVE-2025-20229, CVSS 8.0, risk "high"). The update to Splunk Enterprise 9.4.0, 9.3.3, 9.2.5, 9.1.8 or newer fixes the bug, for the cloud platform Splunk takes care of monitoring and applying the patches.

Sensitive information can also be leaked due to a vulnerability in the Splunk Secure Gateway. Users with restricted rights can then start a search with elevated rights and thus gain unauthorized access to information. When calling a REST endpoint, user session and authorization tokens can end up in plain text in the "splunk_secure_gateway.log". Attackers can exploit this by tricking a victim into starting a request in their web browser and thus "phishing" the data. These gaps are closed by Splunk Enterprise versions 9.4.1, 9.3.3, 9.2.5, 9.1.8 and newer.

Videos by heise

The Splunk developers are also classifying some gaps in third-party components that are delivered with Splunk software. These include Splunk App for Data Science and Deep Learning, Splunk DB Connect, Splunk Infrastructure Monitoring Add-on and Splunk Enterprise. Splunk also warns of other vulnerabilities with a medium or low threat level and provides updates to fix the problems.

The individual security notifications are sorted by severity of the vulnerabilities in descending order:

Cisco acquired Splunk a year ago. Shortly afterwards, the developers began linking the Splunk functions with the Cisco software. One of the first software integrations involved Cisco's AppDynamics.

(dmk)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.