PT-2023-27244 · Solarwinds · Solarwinds Platform
CVE-2023-40061
·
Publicado
2023-11-01
·
Atualizado
2023-12-28
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SolarWinds Platform version 2023.4
Description
The issue is related to an insecure job execution mechanism, which can lead to other attacks. This vulnerability may result in Denial of Service (DoS) or Cross-Site Scripting (XSS) attacks.
Recommendations
For SolarWinds Platform version 2023.4, update to a version that includes the fix for the insecure job execution mechanism vulnerability.
As a temporary workaround, consider restricting access to the job execution mechanism to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Solarwinds Platform