CVE-2023-30956
Last modified
CVE-2023-30956 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0. . EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Palantir | Foundry Comments | < 2.267.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30956?
How severe is CVE-2023-30956?
How do I fix CVE-2023-30956?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3095Improper Access Control in GitHub repository nilsteampassnet…6.5
- CVE-2023-30950The foundry campaigns service was found to be vulnerable to …5.9
- CVE-2023-30951The Foundry Magritte plugin rest-source was found to be vuln…6.5
- CVE-2023-30952A security defect was discovered in Foundry Issues that enab…4.3
- CVE-2023-30954The Gotham video-application-server service contained a race…3.7
- CVE-2023-30955A security defect was identified in Foundry workspace-server…5.4
- CVE-2023-30958A security defect was identified in Foundry Frontend that en…6.1
- CVE-2023-30959In Apollo change requests, comments added by users could co…5.4
- CVE-2023-3096A vulnerability was found in KylinSoft kylin-software-proper…7.8
- CVE-2023-30960A security defect was discovered in Foundry job-tracker that…4.3
- CVE-2023-30961Palantir Gotham was found to be vulnerable to a bug where un…6.1
- CVE-2023-30962The Gotham Cerberus service was found to have a stored cross…5.4
Are you affected by CVE-2023-30956?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
