Lucene search

K
cvePalantirCVE-2023-30955
HistoryJun 29, 2023 - 7:15 p.m.

CVE-2023-30955

2023-06-2919:15:08
CWE-602
CWE-863
Palantir
web.nvd.nist.gov
10
cve-2023-30955
foundry workspace-server
authorization bypass
developer mode
security fix
nvd

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

17.7%

A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to ‘Developer Mode’. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with workspace-server 7.7.0.

Affected configurations

Nvd
Node
palantirfoundry_workspace-serverRange<7.7.0
VendorProductVersionCPE
palantirfoundry_workspace-server*cpe:2.3:a:palantir:foundry_workspace-server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Palantir",
    "product": "com.palantir.workspace:workspace",
    "versions": [
      {
        "version": "*",
        "versionType": "semver",
        "lessThan": "7.7.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

17.7%

Related for CVE-2023-30955