Third-Party Package Updates in Symantec Data Loss Prevention App - April 2025

Advisory ID: SVD-2025-0408

CVE ID:  Multiple

Published: 2025-04-09

Last Update: 2025-04-09

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Symantec Data Loss Prevention App version 2.2.1 and higher, including the following:

PackageRemediationCVESeverity
certifi1Package RemovedCVE-2022-23491High
urllib32Package RemovedCVE-2023-43804High
libxml23Upgraded to 2.12.9MultipleHigh
zlib4Upgraded to 1.3.1CVE-2022-37434Critical
libxslt5Upgraded to 1.1.42CVE-2021-30560Critical
lxml6Upgraded to 5.3.0CVE-2022-2309High

1 Symantec Data Loss Prevention removed the certifi in symantecdlp/wheels/shared folder to remedy CVE-2022-23491

2 Symantec Data Loss Prevention removed the urllib3 in symantecdlp/wheels/shared folder to remedy CVE-2023-43804

3 Symantec Data Loss Prevention upgraded libxml2 in symantecdlp/wheels folder to remedy multiple CVE’s

4 Symantec Data Loss Prevention upgraded zlib in symantecdlp/wheels folder to remedy CVE-2022-37434

5 Symantec Data Loss Prevention upgraded libxslt in symantecdlp/wheels folder to remedy CVE-2021-30560

6 Symantec Data Loss Prevention upgraded lxml in symantecdlp/wheels folder to remedy CVE-2022-2309

Solution

Upgrade Symantec Data Loss Prevention to version 2.2.1 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Symantec Data Loss Prevention2.2.1Below 2.2.12.2.1

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.