Email from securitycontacts@solarwinds.com below. It's very confusing because the last line in the steps to resolve it is to install HF3, which I already have. So does this mean to roll back to HF1, and then install HF3 into that?
My problem w/ going back to HF1 is that's the release we just moved away from to try stopping the constant OAuth authorization errors, which was a total nightmare. It's not been FULLY resolved, but it's much better than it was. Are we not able to modify the ParseExcel.pm file directly, or is the referenced line only a "result" of the fix being in place, rather than the missing line being the actual problem?
I honestly don't think we have the option to go back to HF1. It was causing too many problems and seriously affecting workflows.
By the way, I no longer install over old versions. I remove old versions completely and do fresh installs of every new upgrade. Updating conf files is no big deal because I'd rather did a few quick edits than end up with more corrupted upgrade installs. So whatever comes in HF2, that's what we have. Nothing from HF1 was there to overwrite.
Lastly, does WHD parse Excel files? Maybe only when importing??? When downloading a TSV, that's compiling, right? Not parsing?
NVD - CVE-2023-7101
Thoughts?
