November 2023 Third-Party Package Updates in Splunk Enterprise
Advisory ID: SVD-2023-1106
CVE ID: Multiple
Last Update: 2023-11-16
Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in version 9.1.2308 of Splunk Enterprise Cloud.
|bottle||Upgraded to 0.12.25||CVE-2022-31799|
|python||Upgraded to 3.7.17||CVE-2023-24329|
|openssl||Upgraded to 1.0.2zi||CVE-2023-3817|
|openssl||Upgraded to 1.0.2zi||CVE-2023-3446|
Splunk is actively upgrading and monitoring instances of Splunk Enterprise Cloud.
|Product||Version||Component||Affected Version||Fix Version|
|Splunk Cloud||-||Splunk Web||Below 9.1.2308||9.1.2308|
For the CVEs in this list, Splunk adopted the national vulnerability database (NVD) common vulnerability scoring system (CVSS) rating to align with industry standards.