Third-Party Package Updates in Python for Scientific Computing - November 2024

Advisory ID: SVD-2024-1101

CVE ID: Multiple

Published: 2024-11-26

Last Update: 2024-11-26

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Python for Scientific Computing versions 3.2.2, 4.2.2 and higher. including the following:

PackageRemediationCVESeverity
OpenSSLUpgraded to 3.3.2CVE-2024-5535Low

Solution

Upgrade Python for Scientific Computing (PSC) to version 3.2.2, 4.2.2 or higher.

For Splunk Machine Learning Toolkit (MLTK), upgrading PSC to 4.2.2 requires updating MLTK to 5.5.0 or higher. See Upgrade the Splunk Machine Learning Toolkit for help upgrading and Install the Splunk Machine Learning Toolkit for more information on the version compatibility.

For Splunk IT Service Intelligence (ITSI), upgrading PSC to 4.2.2 may cause errors with ITSI Predictive Analytics. After upgrading, ITSI Predictive Analytics models may require retraining. See Retrain a predictive model in ITSI for more information.

Product Status

ProductVersionComponentAffected VersionFix Version
Python for Scientific Computing (for Linux 64-bit)4.24.2.14.2.2
Python for Scientific Computing (for Mac Apple Silicon)4.24.2.14.2.2
Python for Scientific Computing (for Mac Intel)4.24.2.14.2.2
Python for Scientific Computing (for Windows 64-bit)4.24.2.14.2.2
Python for Scientific Computing (for Linux 64-bit)3.23.2.13.2.2
Python for Scientific Computing (for Mac Apple Silicon)3.23.2.13.2.2
Python for Scientific Computing (for Mac Intel)3.23.2.13.2.2
Python for Scientific Computing (for Windows 64-bit)3.23.2.13.2.2

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating.