Vulnerability Description
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with workspace-server 7.7.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Palantir | Foundry Workspace-Server | < 7.7.0 |
Related Weaknesses (CWE)
References
- https://palantir.safebase.us/?tcuUid=0c3f6c33-4eb0-48b5-ab87-fe48c46a4170Vendor Advisory
- https://palantir.safebase.us/?tcuUid=0c3f6c33-4eb0-48b5-ab87-fe48c46a4170Vendor Advisory
FAQ
What is CVE-2023-30955?
CVE-2023-30955 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient pr...
How severe is CVE-2023-30955?
CVE-2023-30955 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30955?
Check the references section above for vendor advisories and patch information. Affected products include: Palantir Foundry Workspace-Server.