In a recent announcement, SolarWinds has rolled out the 2023.4.2 service update for its platform. Released on November 28, 2023, this update focuses on resolving bugs and enhancing security measures following the prior 2023.4 release.
Among the notable improvements included in the 2023.4.2 release are fixes aimed at addressing specific issues encountered by users during system upgrades. One such fix, identified as Case Number 01494033, resolves a Configuration Wizard failure that occurred during upgrades from earlier versions, including 2020.2.1, 2020.2.4, and 2020.2.5.
However, the most critical aspect of this update relates to security. SolarWinds has addressed a significant vulnerability, CVE-2023-40056. This vulnerability, categorized with a severity rating of 8.0 (High), concerns an SQL Injection Remote Code Execution Vulnerability found within the SolarWinds Platform. The vulnerability's exploit potential is linked to accounts with low privileges. It was detected by Alex Birnberg in collaboration with Trend Micro Zero Day Initiative.
SolarWinds urges users to consult the SolarWinds Platform 2023.4 Release Notes for comprehensive information about the 2023.4 update, which includes End-of-Life (EOL) notices and guidance on system upgrades.
Users seeking further details, including installation instructions and updates, are encouraged to refer to SolarWinds' official documentation and support channels.