Third-Party Package Updates in Splunk Add-on for JBoss - January 2025

Advisory ID: SVD-2025-0102

CVE ID:  Multiple

Published: 2025-01-07

Last Update: 2025-01-07

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Add-on for JBoss versions 3.1.1 and higher, including the following:

PackageRemediationCVESeverity
org.jboss.xnio:xnio-nioUpgraded to 3.8.16CVE-2020-14340Medium
org.jboss.xnio:xnio-apiUpgraded to 3.8.16CVE-2023-5685High
org.jboss.remoting:jboss-remotingUpgraded to 5.0.29CVE-2020-35510Medium

Solution

Upgrade Splunk Add-on for JBoss to version 3.1.1 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Splunk Add-on for JBossBelow 3.1.13.1.1

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.