CVE-2024-29004: SolarWinds Platform Stored XSS Vulnerability
The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Platformto a version that resolves this vulnerability.Fixed in 2024.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29004?
CVE-2024-29004 is considered a high-severity vulnerability due to its potential impact when exploited.
How do I fix CVE-2024-29004?
To remediate CVE-2024-29004, upgrade the SolarWinds Platform to version 2024.3 or later.
Who is affected by CVE-2024-29004?
CVE-2024-29004 affects users of the SolarWinds Platform version 2024.2 and earlier.
What type of vulnerability is CVE-2024-29004?
CVE-2024-29004 is a stored cross-site scripting (XSS) vulnerability affecting the web console.
What is required to exploit CVE-2024-29004?
Exploitation of CVE-2024-29004 requires user interaction and involves high-privileged users.