MEDIUM🇵🇱 Wersja polska

CVE-2023-30959

CVSS 4.1v3.1pub. 2023-09-27upd. 2024-11-21

In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
  • Palantir Apollo Autopilot

    APP
    Palantir
    < 3.308.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2023-30967CRITICAL9.8PL ✓same vendor

Path Traversal w Palantir Gotham Orbital-Simulator — nieautoryzowany odczyt plików

CVE-2023-30945CRITICAL9.8PL ✓same vendor

Nieuwierzytelniony odczyt/zapis plików w Palantir VHS, VCD i Clips2

CVE-2023-30969HIGH8.2same vendor

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not perform...

CVE-2023-22835HIGH7.7same vendor

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack b...

CVE-2023-22833HIGH7.6same vendor

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that all...