Third-Party Package Updates in Kafka App - April 2025

Advisory ID: SVD-2025-0412

CVE ID: Multiple

Published: 2025-04-09

Last Update: 2025-04-09

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Kafka version 2.0.8 and higher, including the following:

PackageRemediationCVESeverity
pcre1Upgraded to pcre2 10.32MultipleHigh

1 Kafka upgraded pcre to pcre2 in kafka/wheels/py39/gssapi-1.7.3-cp39-cp39-manylinux_2_28_x86_64l/gssapi.libs folder to remedy multiple CVE’s

Solution

Upgrade Kafka to version 2.0.8 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Kafka2.0.8Below 2.0.82.0.8

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.