Lucene search

K
cvePalantirCVE-2023-30954
HistoryNov 15, 2023 - 8:15 p.m.

CVE-2023-30954

2023-11-1520:15:07
CWE-285
CWE-362
Palantir
web.nvd.nist.gov
30
cve-2023-30954
gotham
video application server
race condition
acls
new videos
source system
initialization
nvd

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0.001

Percentile

17.0%

The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized.

Affected configurations

Nvd
Node
palantirvideo-application-serverRange<2.206.1
VendorProductVersionCPE
palantirvideo-application-server*cpe:2.3:a:palantir:video-application-server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Palantir",
    "product": "com.palantir.video:video-application-server",
    "versions": [
      {
        "version": "*",
        "versionType": "semver",
        "lessThan": "2.206.1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0.001

Percentile

17.0%

Related for CVE-2023-30954