A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.
References
Link | Resource |
---|---|
https://palantir.safebase.us/?tcuUid=40367943-738c-4e69-b852-4a503c77478a | Vendor Advisory |
https://palantir.safebase.us/?tcuUid=40367943-738c-4e69-b852-4a503c77478a | Vendor Advisory |
Configurations
History
21 Nov 2024, 08:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://palantir.safebase.us/?tcuUid=40367943-738c-4e69-b852-4a503c77478a - Vendor Advisory |
18 Jul 2023, 19:51
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://palantir.safebase.us/?tcuUid=40367943-738c-4e69-b852-4a503c77478a - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
First Time |
Palantir
Palantir foundry Comments |
|
CPE | cpe:2.3:a:palantir:foundry_comments:*:*:*:*:*:*:*:* |
10 Jul 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-10 22:15
Updated : 2024-11-21 08:01
NVD link : CVE-2023-30956
Mitre link : CVE-2023-30956
CVE.ORG link : CVE-2023-30956
JSON object : View
Products Affected
palantir
- foundry_comments
CWE