Vulnerability Description
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Palantir | Gotham Blackbird-Witchcraft | >= 10.1, < 104.30231001.8 |
| Palantir | Gotham Static-Assets-Servlet | < 1.1.0 |
Related Weaknesses (CWE)
References
- https://palantir.safebase.us/?tcuUid=69be99ef-ad24-4339-9017-c8bf70789c72Vendor Advisory
- https://palantir.safebase.us/?tcuUid=69be99ef-ad24-4339-9017-c8bf70789c72Vendor Advisory
FAQ
What is CVE-2023-30970?
CVE-2023-30970 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
How severe is CVE-2023-30970?
CVE-2023-30970 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30970?
Check the references section above for vendor advisories and patch information. Affected products include: Palantir Gotham Blackbird-Witchcraft, Palantir Gotham Static-Assets-Servlet.