CVE-2024-29003: SolarWinds Platform Cross Site Scripting Vulnerability
The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Platformto a version that resolves this vulnerability.Fixed in 2024.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29003?
CVE-2024-29003 is classified as a moderate severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-29003?
To mitigate CVE-2024-29003, update your SolarWinds Platform to version 2024.1.1 or later.
Is user authentication required for CVE-2024-29003?
Yes, CVE-2024-29003 requires user authentication and interaction to exploit.
Which versions of SolarWinds Platform are affected by CVE-2024-29003?
CVE-2024-29003 affects all versions of SolarWinds Platform prior to 2024.1.1.
What impact does CVE-2024-29003 have on users?
CVE-2024-29003 could allow an authenticated attacker to execute malicious scripts in the context of the user's session.