SolarWinds Observability Self-Hosted 2024.4.1 release notes
Release date: December 4, 2024
SolarWinds Observability Self-Hosted 2024.4.1 is a service release providing bug and security fixes for release 2024.4. For information about the SolarWinds Observability Self-Hosted release, including EOL notices and upgrade information, see SolarWinds Observability Self-Hosted 2024.4 Release Notes.
SolarWinds Observability Self-Hosted runs on the SolarWinds Platform (self-hosted). SolarWinds Observability Self-Hosted release notes include the updates from the SolarWinds Platform (self-hosted).
Fixed CVEs
At SolarWinds, we prioritize the swift resolution of CVEs to ensure the security and integrity of our software. In this release, we have successfully addressed the following CVEs.
SolarWinds CVEs
SolarWinds would like to thank our Security Researchers below for reporting on the issue in a responsible manner and working with our security, product, and engineering teams to fix the vulnerability.
CVE-ID | Vulnerability Title | Description | Severity | Credit |
---|---|---|---|---|
CVE-2024-45717 | SolarWinds Platform Cross Site Scripting Vulnerability | The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication and requires user interaction. | 7.0 High | Frank Lycops, NATO Cyber Security Centre |
Third-party CVEs
CVE-ID | Vulnerability title | Description | Severity |
---|---|---|---|
CVE-2024-43483 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | 7.5 High |
CVE-2024-38167 | .NET and Visual Studio Information Disclosure Vulnerability | .NET and Visual Studio Information Disclosure Vulnerability | 6.5 Medium |
CVE-2024-43485 | .NET and Visual Studio Denial of Service Vulnerability | .NET and Visual Studio Denial of Service Vulnerability | 7.5 High |
Fixed customer issues
Case number | Description | Platform product |
---|---|---|
01787803 | In environments that make heavy use of the WMI polling method, WMI polling no longer fails with the message |
Platform |
01775614, 01797044 | If the National Institute of Standards and Technology (NIST) does not include data about a device type in the Common Platform Enumeration (CPE) Dictionary, the missing data no longer prevents SolarWinds Observability Self-Hosted from identifying firmware vulnerabilities that affect the device. |
Platform |
01790612, 01795074 | The Incident Number column on the All Active Alerts page displays the number of currently active incidents associated with an alert. It no longer includes incidents that occurred in the past and are no longer active. |
Platform |
01778801 | Information that should not be available to a user because of limitations is no longer exposed in certain situations, such as a failed service initialization on an unstable database connection. |
Platform |
01791756, 01800049 | Upgrading the SolarWinds Platform log database no longer fails with an error similar to the following if the database is contained:
|
Platform |
01785463, 01785499, 01786391, 01787163, 01787867, 01790533, 01791274, 01799572 | When you open the Deployment Health tab from an additional web server, health checks run correctly. |
Platform |
01742235 | Maps created without a container can be updated and saved. |
Platform |
01761260 | Using a date format other than MM/DD/YYYY no longer prevents the discovery of a Power Control Unit (PCU). |
Platform |
01803929 | When a subgroup is added to a map, the All Groups widget and Manage Groups page no longer display the subgroup as both a root level group and a subgroup. |
Platform |
01788280 | When you select the $Name variable under Map name format, you can save the map definition. |
Platform |
01682272, 01749347 | If a polling engine is upgraded to 2024.4 or later but agents remain on an older version, CPU data is not missing for agent-monitored Windows servers. |
Platform |
01781723, 01781959, 01782050 | Having data in the table
|
NCM |
01792541, 01795162, 01795195, 01796124, 01796169, 01797347, 01798129, 01798638, 01798748, 01799802, 01800337, 01801313, 01801526, 01802303 | The weight for some WMI interfaces on agent nodes is no longer recorded as less than 0. This issue caused database maintenance to fail with the error |
NPM |
01774825 | Recent changes to the Aruba Central API introduced a restriction that limits the initial authentication call ( NPM 2024.4.1 provides an update that enables it to poll Aruba devices correctly with this restriction. |
NPM |
01780800 | Aruba Orchestrator tunnels are polled even if the interface device ID cannot be identified. |
NPM |
01737115 | When an Arista device reports the RouteAge value as -1, the Top 10 Flapping Routes widget no longer displays duplicate values. |
NPM |
01783597, 01787060 | Duplicate device types for FortinetFortiManager Orchestrator devices in the SolarWinds Platform database are removed. This situation no longer causes upgrades to fail with the following message:
|
NPM |
01768169 | When the response from a Juniper Mist device does not include a MAC address, polling the device no longer fails and the device is not shown as down. |
NPM |
01586566, 01741532, 01766039, 01776895 | The aggregation type
|
SAM |
01426384, 01498206, 01683804, 01764202, 01782904 | Creating, updating, or deleting a large number of containers no longer causes performance problems. |
SAM |
01749163 | Azure subscriptions can be retrieved when a single tenant has more than 50 subscriptions. |
SAM |
01729159, 01800435 | Duplicate hosts are no longer added for Nutanix clusters. |
VMAN |
01737754 | Large values in the destSpan_value column no longer result in call data being dropped and errors such as the following appearing in the IPSLA business layer logs:
|
VNQM |
Legal notices
© 2024 SolarWinds Worldwide, LLC. All rights reserved.
This document may not be reproduced by any means nor modified, decompiled, disassembled, published or distributed, in whole or in part, or translated to any electronic medium or other means without the prior written consent of SolarWinds. All right, title, and interest in and to the software, services, and documentation are and shall remain the exclusive property of SolarWinds, its affiliates, and/or its respective licensors.
SOLARWINDS DISCLAIMS ALL WARRANTIES, CONDITIONS, OR OTHER TERMS, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, ON THE DOCUMENTATION, INCLUDING WITHOUT LIMITATION NONINFRINGEMENT, ACCURACY, COMPLETENESS, OR USEFULNESS OF ANY INFORMATION CONTAINED HEREIN. IN NO EVENT SHALL SOLARWINDS, ITS SUPPLIERS, NOR ITS LICENSORS BE LIABLE FOR ANY DAMAGES, WHETHER ARISING IN TORT, CONTRACT OR ANY OTHER LEGAL THEORY, EVEN IF SOLARWINDS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
The SolarWinds, SolarWinds & Design, Orion, and THWACK trademarks are the exclusive property of SolarWinds Worldwide, LLC or its affiliates, are registered with the U.S. Patent and Trademark Office, and may be registered or pending registration in other countries. All other SolarWinds trademarks, service marks, and logos may be common law marks or are registered or pending registration. All other trademarks mentioned herein are used for identification purposes only and are trademarks of (and may be registered trademarks) of their respective companies.