Security

CVE-2024-5535 - Openssl 1.0.2zj Vunerability

AkhilSreek
New Member

Hey ,


Just heard about CVE-2024-5535 on splunkforwarder agent 9.0.9 for Openssl 1.0.2zj , Is this a real one ? Do we need upgrade the agent now.

 

Thanks in advance.

Labels (3)
0 Karma

marnall
Motivator

Version 9.0.9 of the Splunk Forwarder does contain Openssl 1.0.2zj. Is this version of Openssl vulnerable to CVE-2024-5535? I could not find a direct confirmation.

Latest third-party security update involving openssl: https://advisory.splunk.com/advisories/SVD-2024-0304

As the latest advisory does not include openssl (https://advisory.splunk.com/advisories/SVD-2024-0718) , it may be best to wait for the next patch.

0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...