CVE-2025-0367
Regular Expression Denial of Service (ReDoS) in Splunk Supporting Add-on for Active Directory (SA-ldapsearch)
Exploited
Not listed
EPSS
0.005
41.4th percentile
Discovered by
Not disclosed
Published
Jan 30, 2025
Assigned by splunk
Description
In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.
Weakness: CWE-1333
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Apps & Add-ons | SIEM & Log Management | affected-vendor |
Vendor-reported products (1)
- Splunk · Splunk Supporting Add-on for Active Directory
Credit
Kyle Bambrick, Splunk