CVE-2023-30961
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link.
Affected (3)
Products: Palantir: Gotham Fe Bundle, Titanium Browser App Bundle
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 100.30230702.0 to 100.30230704.15 | |
| Before 100.30230706.20 |
Related CWEs
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
CWE-710
Improper Adherence to Coding Standards
The product does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.
References (2)
Source: cve-coordination@palantir.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.