Third-Party Package Updates in Fidelis Network App - April 2025

Advisory ID: SVD-2025-0403

CVE ID:  Multiple

Published: 2025-04-09

Last Update: 2025-04-09

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Fidelis Network App version 1.0.2 and higher, including the following:

PackageRemediationCVESeverity
certifi1Package RemovedCVE-2022-23491High
urllib32Package RemovedCVE-2023-43804High

1 Fidelis Network removed the wheels folder which contains certifi package to remedy CVE-2022-23491

2 Fidelis Network removed the wheels folder which contains urllib3 package to remedy CVE-2023-43804

Solution

Upgrade Fidelis Network to version 1.0.2 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Fidelis Network1.0.2Below 1.0.21.0.2

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.