CVE-2025-20378 | Splunk Enterprise/Cloud Platform Logendpoint return_to redirect (SVD-2025-1101 / Nessus ID 275170)
A vulnerability described as problematic has been identified in Splunk Enterprise and Cloud Platform. The impacted element is an unknown function of the component Logendpoint. Executing manipulation of the argument return_to can lead to open redirect.
This vulnerability appears as CVE-2025-20378. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.