splunk-sdk@1.6.14 vulnerabilities

The Splunk Software Development Kit for Python.

Direct Vulnerabilities

Known vulnerabilities in the splunk-sdk package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Regular Expression Denial of Service (ReDoS)

splunk-sdk is a Software Development Kit (SDK) for Python that contains library code and examples designed to enable developers to build applications using Splunk.

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via CommandLineParser class in internals.py, due to a problematic regex match occurs which can cause backtracking.

How to fix Regular Expression Denial of Service (ReDoS)?

Upgrade splunk-sdk to version 1.6.16 or higher.

[,1.6.16)