CVE-2023-30952
Last modified
CVE-2023-30952 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 .. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 .
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Palantir | Foundry | < 6.228.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30952?
How severe is CVE-2023-30952?
How do I fix CVE-2023-30952?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30946A security defect was identified in Foundry Issues. If a use…4.3
- CVE-2023-30948A security defect in Foundry's Comments functionality result…6.5
- CVE-2023-30949A missing origin validation in Slate sandbox could be exploi…5.3
- CVE-2023-3095Improper Access Control in GitHub repository nilsteampassnet…6.5
- CVE-2023-30950The foundry campaigns service was found to be vulnerable to …5.9
- CVE-2023-30951The Foundry Magritte plugin rest-source was found to be vuln…6.5
- CVE-2023-30954The Gotham video-application-server service contained a race…3.7
- CVE-2023-30955A security defect was identified in Foundry workspace-server…5.4
- CVE-2023-30956A security defect was identified in Foundry Comments that en…5.3
- CVE-2023-30958A security defect was identified in Foundry Frontend that en…6.1
- CVE-2023-30959In Apollo change requests, comments added by users could co…5.4
- CVE-2023-3096A vulnerability was found in KylinSoft kylin-software-proper…7.8
Are you affected by CVE-2023-30952?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
