CVE-2023-30945
Last modified
CVE-2023-30945 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Palantir | Clips2 | < 0.111.2 |
| Palantir | Video Clip Distributor | < 0.24.10 |
| Palantir | Video History Service | < 2.210.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30945?
How severe is CVE-2023-30945?
How do I fix CVE-2023-30945?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3094A vulnerability classified as critical has been found in cod…9.8
- CVE-2023-30940In telephony service, there is a missing permission check. T…5.5
- CVE-2023-30941In telephony service, there is a missing permission check. T…5.5
- CVE-2023-30942In telephony service, there is a missing permission check. T…5.5
- CVE-2023-30943The vulnerability was found Moodle which exists because the …5.3
- CVE-2023-30944The vulnerability was found Moodle which exists due to insuf…7.3
- CVE-2023-30946A security defect was identified in Foundry Issues. If a use…4.3
- CVE-2023-30948A security defect in Foundry's Comments functionality result…6.5
- CVE-2023-30949A missing origin validation in Slate sandbox could be exploi…5.3
- CVE-2023-3095Improper Access Control in GitHub repository nilsteampassnet…6.5
- CVE-2023-30950The foundry campaigns service was found to be vulnerable to …5.9
- CVE-2023-30951The Foundry Magritte plugin rest-source was found to be vuln…6.5
Are you affected by CVE-2023-30945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
