Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8428 | In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user. |
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-0310 |
|
Fri, 01 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:splunk:splunk_app_for_lookup_file_editing:*:*:*:*:*:*:*:* |
Thu, 27 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user. | |
| Title | Incorrect permissions set by the “chmod“ and “makedirs“ Python functions in Splunk App for Lookup File Editing | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2025-03-27T13:49:03.631Z
Reserved: 2024-10-10T19:15:13.237Z
Link: CVE-2025-20233
Updated: 2025-03-27T13:48:59.609Z
Status : Analyzed
Published: 2025-03-26T22:15:15.390
Modified: 2025-08-01T18:03:30.680
Link: CVE-2025-20233
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:07:20Z
EUVD