CVE-2024-29004: SolarWinds Platform Stored XSS Vulnerability
Published Jun 4, 2024
·Updated
The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds SolarWinds Platform<2024.2
Remediation
Information
SolarWinds recommends that customers upgrade to SolarWinds Platform 2024.2 as soon as it becomes available.
Event History
Jun 4, 2024
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29004?
CVE-2024-29004 is considered a high-severity vulnerability due to its potential impact when exploited.
2
How do I fix CVE-2024-29004?
To remediate CVE-2024-29004, upgrade the SolarWinds Platform to version 2024.3 or later.
3
Who is affected by CVE-2024-29004?
CVE-2024-29004 affects users of the SolarWinds Platform version 2024.2 and earlier.
4
What type of vulnerability is CVE-2024-29004?
CVE-2024-29004 is a stored cross-site scripting (XSS) vulnerability affecting the web console.
5
What is required to exploit CVE-2024-29004?
Exploitation of CVE-2024-29004 requires user interaction and involves high-privileged users.