Third-Party Package Updates in Splunk Universal Forwarder - December 2024

Advisory ID: SVD-2024-1207

CVE ID: CVE-2024-5535

Published: 2024-12-10

Last Update: 2024-12-10

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Universal Forwarder versions 9.1.7, 9.2.4, and 9.3.2, and higher, including the following:

PackageRemediationCVESeverity
OpenSSLUpgraded to 1.0.2zkCVE-2024-5535Informational

Solution

Upgrade Splunk Universal Forwarder to versions 9.1.7, 9.2.4, 9.3.2, or higher.

Product Status

ProductVersionComponentAffected VersionFix Version
Splunk Universal Forwarder9.39.3.0 to 9.3.19.3.2
Splunk Universal Forwarder9.29.2.0 to 9.2.39.2.4
Splunk Universal Forwarder9.19.1.0 to 9.1.69.1.7

Severity

The Splunk Universal Forwarder is not affected by CVE-2024-5535. The implementation does not call SSL_select_next_proto and does not use the functionality. Hence, the severity is informational.