In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:NPalantir Apollo Autopilot
APPPalantir< 3.308.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2023-30967CRITICAL9.8PL ✓same vendor
Path Traversal w Palantir Gotham Orbital-Simulator — nieautoryzowany odczyt plików
CVE-2023-30945CRITICAL9.8PL ✓same vendor
Nieuwierzytelniony odczyt/zapis plików w Palantir VHS, VCD i Clips2
CVE-2023-30969HIGH8.2same vendor
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not perform...
CVE-2023-22835HIGH7.7same vendor
A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack b...
CVE-2023-22833HIGH7.6same vendor
Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that all...