Network Management
Why SolarWinds Observability Self-Hosted is not affected by CVE-2024-53846
This article explains why SolarWinds Observability Self-Hosted is not affected by CVE-2024-53846 SolarWinds Observability Self-Hosted is not affected because, while we deliver the Erlang component version with RabbitMQ, our deployment is not affected by the vulnerability.
First published date
Last published date
Overview
The following details explain why SolarWinds Observability Self-Hosted is not affected:
• The affected ”verify_fun” functionality is required to be vulnerable to this issue. This functionality is not used by SolarWinds and is not implemented by default in Erlang.
• The ”verify_fun” functionality requires local administrator rights to access the configuration, enable the functionality, and configure the extended key capability which is not done by default.
In 2024, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2024-53846.
CVE-2024-53846 is a vulnerability in Erlang that allows the use of resulting in a server or client verifying the peer when incorrect extended key usage is presented.
These are the versions of Erlang that are affected by this vulnerability:
- >= OTP-25.3.2.8
- >= OTP-26.2
- >= OTP-27.01
The vulnerability described in this CVE affects numerous software companies, but it does not impact SolarWinds Observability Self-Hosted.
Product section
Cause
CVE-2024-53846
Resolution
This vulnerability affects only applications that meet all the prerequisites mentioned above.