CVE-2025-20233: Splunk App For Lookup File Editing
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.
Affected products
- Splunk Splunk App For Lookup File Editing: from 4.0.0, before 4.0.5 (fixed in 4.0.5)
Published 2025-03-26. Last modified 2026-06-17.