CVE-2024-28076: SolarWinds Platform Arbitrary Open Redirection Vulnerability
Published Apr 18, 2024
·Updated
The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format
Affected Software
2 affected components
SolarWinds Platform
SolarWinds SolarWinds Platform<2024.1.1
Remediation
Information
SolarWinds recommends that customers upgrade to SolarWinds Platform 2024.1.1 as soon as it becomes available.
Event History
Apr 18, 2024
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Is there a workaround for CVE-2024-28076 if I cannot update immediately?
Currently, there are no recommended workarounds for CVE-2024-28076, and updating is strongly advised to ensure protection.