Third-Party Package Updates in the Splunk Add-on for Cisco Meraki - October 2024

Advisory ID: SVD-2024-1015

CVE ID:  Multiple

Published: 2024-10-30

Last Update: 2024-10-30

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in the Splunk Add-on for Cisco Meraki version 2.2.0 and higher, including the following:

PackageRemediationCVESeverity
idnaUpgraded to 3.8CVE-2024-3651High
urllib3Upgraded to 1.26.20CVE-2024-37891Medium
tqdmRemovedCVE-2024-34062Medium
certifiUpgraded to 2024.8.30CVE-2024-39689High

Solution

Upgrade Splunk Add-on for Cisco Meraki versions 2.2.0 or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Splunk Add-on for Cisco Meraki2.2Below 2.2.02.2.0

Severity

For the CVEs in this list, Splunk adopted one of the following ratings:
- Where applicable, the severity rating that the vendor published, or
- The national vulnerability database (NVD) common vulnerability scoring system (CVSS) rating, otherwise.