Intel

AIKIDO-2024-10406

splunk-sdk is vulnerable to Inadequate Encryption Strength

Inadequate Encryption Strength Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 4, 2024

50

Medium Risk

This Affects:

pythonsplunk-sdk
1.0 - 2.0.2
Fixed in 2.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package use insecure TLS 1.0 and TLS 1.1 protocols, which are vulnerable to man-in-the-middle attacks. This exposes data to potential interception and manipulation, compromising both confidentiality and integrity.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

splunk-sdk is vulnerable to Inadequate Encryption Strength in versions 1.0 - 2.0.2.

How to fix this

Upgrade the splunk-sdk library to the patch version.