CVE-2023-30946
Last modified
CVE-2023-30946 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query Foundry's Notification API and receive metadata about the issue including the RID of the issue, severity, internal UUID of the author, and the user-defined title of the issue.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query Foundry's Notification API and receive metadata about the issue including the RID of the issue, severity, internal UUID of the author, and the user-defined title of the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Palantir | Foundry Issues | < 2.497.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30946?
How severe is CVE-2023-30946?
How do I fix CVE-2023-30946?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30940In telephony service, there is a missing permission check. T…5.5
- CVE-2023-30941In telephony service, there is a missing permission check. T…5.5
- CVE-2023-30942In telephony service, there is a missing permission check. T…5.5
- CVE-2023-30943The vulnerability was found Moodle which exists because the …5.3
- CVE-2023-30944The vulnerability was found Moodle which exists due to insuf…7.3
- CVE-2023-30945Multiple Services such as VHS(Video History Server) and VCD(…9.8
- CVE-2023-30948A security defect in Foundry's Comments functionality result…6.5
- CVE-2023-30949A missing origin validation in Slate sandbox could be exploi…5.3
- CVE-2023-3095Improper Access Control in GitHub repository nilsteampassnet…6.5
- CVE-2023-30950The foundry campaigns service was found to be vulnerable to …5.9
- CVE-2023-30951The Foundry Magritte plugin rest-source was found to be vuln…6.5
- CVE-2023-30952A security defect was discovered in Foundry Issues that enab…4.3
Are you affected by CVE-2023-30946?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
