Vulnerability Description
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Palantir | Gotham Cerberus | < 100.230704.0-27-g031dd58 |
Related Weaknesses (CWE)
References
- https://palantir.safebase.us/?tcuUid=92dd599a-07e2-43a8-956a-9c9566794be0Vendor Advisory
- https://palantir.safebase.us/?tcuUid=92dd599a-07e2-43a8-956a-9c9566794be0Vendor Advisory
FAQ
What is CVE-2023-30962?
CVE-2023-30962 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vu...
How severe is CVE-2023-30962?
CVE-2023-30962 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30962?
Check the references section above for vendor advisories and patch information. Affected products include: Palantir Gotham Cerberus.