Third-Party Package Updates in Splunk Operator for Kubernetes - June 2025

Advisory ID: SVD-2025-0609

CVE ID:  Multiple

Published: 2025-06-23

Last Update: 2025-06-23

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Splunk Operator for Kubernetes version 2.8.0, and higher, including the following:

PackageRemediationCVESeverity
golang.org/grpcUpgraded to 1.58.3CVE-2023-44487High
github.com/golang-jwt/jwt/v5Upgraded to 5.2.2CVE-2025-30204High
go://golang.org/x/netUpgraded to 0.36.0CVE-2025-22870Medium

Solution

Upgrade Splunk Operator for Kubernetes to version 2.8.0 or higher.

See Splunk Operator for Kubernetes releases

Product Status

ProductBase VersionAffected VersionFix Version
Splunk Operator for Kubernetes2.8Below 2.8.02.8.0

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.