First published: Thu Jun 15 2023(Updated: )
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request. Part of the URL of the request discloses sensitive data.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U | <15.4 |
SolarWinds recommends customers upgrade to SolarWinds Serv-U version 15.4 as soon as it becomes available. The expected release date is May 17, 2023.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23841 is a vulnerability in SolarWinds Serv-U that allows sensitive data to be disclosed in the URL of an HTTP request when changing or updating attributes for File Share or File request.
CVE-2023-23841 has a severity rating of 7.5 (high).
CVE-2023-23841 affects SolarWinds Serv-U by exposing sensitive data in the URL of an HTTP request.
To fix CVE-2023-23841, it is recommended to upgrade SolarWinds Serv-U to a version that is not affected by this vulnerability.
More information about CVE-2023-23841 can be found in the SolarWinds Serv-U release notes and security advisories.