CVE-2023-30945

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:palantir:clips2:*:*:*:*:*:*:*:*
cpe:2.3:a:palantir:video_clip_distributor:*:*:*:*:*:*:*:*
cpe:2.3:a:palantir:video_history_service:*:*:*:*:*:*:*:*

History

05 Jul 2023, 18:14

Type Values Removed Values Added
CPE cpe:2.3:a:palantir:clips2:*:*:*:*:*:*:*:*
cpe:2.3:a:palantir:video_history_service:*:*:*:*:*:*:*:*
cpe:2.3:a:palantir:video_clip_distributor:*:*:*:*:*:*:*:*
References (MISC) https://palantir.safebase.us/?tcuUid=e62e4dad-b39b-48ba-ba30-7b7c83406ad9 - (MISC) https://palantir.safebase.us/?tcuUid=e62e4dad-b39b-48ba-ba30-7b7c83406ad9 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Palantir
Palantir video Clip Distributor
Palantir video History Service
Palantir clips2
CWE CWE-22

26 Jun 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-26 23:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-30945

Mitre link : CVE-2023-30945

CVE.ORG link : CVE-2023-30945


JSON object : View

Products Affected

palantir

  • clips2
  • video_history_service
  • video_clip_distributor
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-287

Improper Authentication