Third-Party Package Updates in Splunk Add-on for Office 365 - October 2024

Advisory ID: SVD-2024-1013

CVE ID:  Multiple

Published: 2024-10-17

Last Update: 2024-10-17

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Add-on for Office 365 versions 4.5.2 and higher, including the following:

PackageRemediationCVESeverity
idnaUpgraded to 3.7CVE-2024-3651High
urllib3Upgraded to 1.26.19CVE-2024-37891Medium
certifiUpgraded to 2024.7.4CVE-2024-39689High
requestsUpgraded to 2.31.0CVE-2023-32681Medium

Solution

Upgrade Splunk Add-on for Office 365 versions 4.5.2 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Splunk Add-on for Office 3654.5.2Below 4.5.24.5.2

Severity

For the CVEs in this list, Splunk adopted one of the following ratings:
- Where applicable, the severity rating that the vendor published, or
- The national vulnerability database (NVD) common vulnerability scoring system (CVSS) rating, otherwise.