Third-Party Package Updates in Python for Scientific Computing - November 2024
Advisory ID: SVD-2024-1101
CVE ID: Multiple
Published: 2024-11-26
Last Update: 2024-11-26
Description
Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Python for Scientific Computing versions 3.2.2, 4.2.2 and higher. including the following:
Package | Remediation | CVE | Severity |
---|---|---|---|
OpenSSL | Upgraded to 3.3.2 | CVE-2024-5535 | Low |
Solution
Upgrade Python for Scientific Computing (PSC) to version 3.2.2, 4.2.2 or higher.
For Splunk Machine Learning Toolkit (MLTK), upgrading PSC to 4.2.2 requires updating MLTK to 5.5.0 or higher. See Upgrade the Splunk Machine Learning Toolkit for help upgrading and Install the Splunk Machine Learning Toolkit for more information on the version compatibility.
For Splunk IT Service Intelligence (ITSI), upgrading PSC to 4.2.2 may cause errors with ITSI Predictive Analytics. After upgrading, ITSI Predictive Analytics models may require retraining. See Retrain a predictive model in ITSI for more information.
Product Status
Product | Version | Component | Affected Version | Fix Version |
---|---|---|---|---|
Python for Scientific Computing (for Linux 64-bit) | 4.2 | 4.2.1 | 4.2.2 | |
Python for Scientific Computing (for Mac Apple Silicon) | 4.2 | 4.2.1 | 4.2.2 | |
Python for Scientific Computing (for Mac Intel) | 4.2 | 4.2.1 | 4.2.2 | |
Python for Scientific Computing (for Windows 64-bit) | 4.2 | 4.2.1 | 4.2.2 | |
Python for Scientific Computing (for Linux 64-bit) | 3.2 | 3.2.1 | 3.2.2 | |
Python for Scientific Computing (for Mac Apple Silicon) | 3.2 | 3.2.1 | 3.2.2 | |
Python for Scientific Computing (for Mac Intel) | 3.2 | 3.2.1 | 3.2.2 | |
Python for Scientific Computing (for Windows 64-bit) | 3.2 | 3.2.1 | 3.2.2 |
Severity
For the CVEs in this list, Splunk adopted the vendor’s severity rating.