Third-Party Package Updates in ProtectWise App - April 2025

Advisory ID: SVD-2025-0407

CVE ID:  Multiple

Published: 2025-04-09

Last Update: 2025-04-09

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in ProtectWise App version 2.1.1 and higher, including the following:

PackageRemediationCVESeverity
certifi1Package RemovedCVE-2022-23491High
urllib32Package RemovedCVE-2023-43804High

1 ProtectWise removed the wheels folder which contains certifi package to remedy CVE-2022-23491

2 ProtectWise removed the wheels folder which contains urllib3 package to remedy CVE-2023-43804

Solution

Upgrade ProtectWise to version 2.1.1 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
ProtectWise2.1.1Below 2.1.12.1.1

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.