Third-Party Package Updates in Splunk Add-on for Amazon Web Services - September 2024

Advisory ID: SVD-2024-0901

CVE ID:  Multiple

Published: 2024-09-30

Last Update: 2024-09-30

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Add-on for Amazon Web Services versions 7.7.0 and higher, including the following:

PackageRemediationCVESeverity
idnaUpgraded to 3.7CVE-2024-3651High
urllib3Upgraded to 1.26.19CVE-2024-37891Medium
golang1Upgraded golang to 1.22.5CVE-2023-39326Medium
certifiUpgraded to 2024.7.4CVE-2024-39689High

1 Upgraded parquet_decoder_darwin_amd64, parquet_decoder_linux_amd64, and parquet_decoder_windows_amd64.exe in Splunk_TA_aws/bin/aws_parquet/ from 1.19.8 to 1.22.5.

Solution

Upgrade Splunk Add-on for Amazon Web Services to versions 7.7.0 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Splunk Add-on for Amazon Web Services7.7Below 7.7.07.7.0

Severity

For the CVEs in this list, Splunk adopted one of the following ratings:
- Where applicable, the severity rating that the vendor published, or
- The national vulnerability database (NVD) common vulnerability scoring system (CVSS) rating, otherwise.