MEDIUM🇵🇱 Wersja polska

CVE-2023-30970

CVSS 6.5v3.1pub. 2024-01-29upd. 2024-11-21

Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Palantir Gotham Blackbird Witchcraft

    APP
    Palantir
    10.1 – 104.30231001.8 (excl.)10.2 – 104.30231002.10 (excl.)10.3 – 104.30231003.9 (excl.)9.8 – 104.30230908.21 (excl.)8.7 – 104.30230807.59 (excl.)6.4 – 104.30230604.81 (excl.)3.4 – 103.30230304.433 (excl.)
  • Palantir Gotham Static Assets Servlet

    APP
    Palantir
    < 1.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2023-30967CRITICAL9.8PL ✓same vendor

Path Traversal w Palantir Gotham Orbital-Simulator — nieautoryzowany odczyt plików

CVE-2023-30945CRITICAL9.8PL ✓same vendor

Nieuwierzytelniony odczyt/zapis plików w Palantir VHS, VCD i Clips2

CVE-2023-30969HIGH8.2same vendor

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not perform...

CVE-2023-22835HIGH7.7same vendor

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack b...

CVE-2023-22833HIGH7.6same vendor

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that all...