Third-Party Package Updates in NetWitness Logs and Packets App - April 2025

Advisory ID: SVD-2025-0410

CVE ID:  Multiple

Published: 2025-04-09

Last Update: 2025-04-09

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in NetWitness Logs and Packets version 3.0.0 and higher, including the following:

PackageRemediationCVESeverity
certifi1Package RemovedCVE-2022-23491High
urllib32Package RemovedCVE-2023-43804High

1 NetWitness Logs and Packets removed the wheels folder which contains certifi package to remedy CVE-2022-23491

2 NetWitness Logs and Packets removed the wheels folder which contains urllib3 package to remedy CVE-2023-43804

Solution

Upgrade NetWitness Logs and Packets to version 3.0.0 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
NetWitness Logs and Packets3.0.0Below 3.0.03.0.0

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.