Vulnerability Description
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Palantir | Apollo Autopilot | < 3.308.0 |
Related Weaknesses (CWE)
References
- https://palantir.safebase.us/?tcuUid=4c257f07-58af-4532-892a-bdbe8ab3ec63Third Party Advisory
- https://palantir.safebase.us/?tcuUid=4c257f07-58af-4532-892a-bdbe8ab3ec63Third Party Advisory
FAQ
What is CVE-2023-30959?
CVE-2023-30959 is a vulnerability with a CVSS score of 4.1 (MEDIUM). In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
How severe is CVE-2023-30959?
CVE-2023-30959 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30959?
Check the references section above for vendor advisories and patch information. Affected products include: Palantir Apollo Autopilot.