Third-Party Package Updates in PagerDuty App - April 2025

Advisory ID: SVD-2025-0405

CVE ID:  Multiple

Published: 2025-04-09

Last Update: 2025-04-09

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in PagerDuty version 3.0.0 and higher, including the following:

PackageRemediationCVESeverity
certifi1Package RemovedCVE-2022-23491High
urllib32Package RemovedCVE-2023-43804High

1 PagerDuty removed the wheels folder which contains certifi package to remedy CVE-2022-23491

2 PagerDuty removed the wheels folder which contains urllib3 package to remedy CVE-2023-43804

Solution

Upgrade PagerDuty to version 3.0.0 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
PagerDuty3.0.0Below 3.0.03.0.0

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.