Lucene search

K
cvelistPalantirCVELIST:CVE-2023-30955
HistoryJun 29, 2023 - 6:46 p.m.

CVE-2023-30955 Foundry workspace-server Developer Mode Authorization Bypass

2023-06-2918:46:33
CWE-602
Palantir
www.cve.org
2
cve-2023-30955
foundry workspace-server
developer mode
authorization bypass
security defect
authorization check
developer mode settings
insufficient privilege
fix deployed
7.7.0

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

17.7%

A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to ‘Developer Mode’. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with workspace-server 7.7.0.

CNA Affected

[
  {
    "vendor": "Palantir",
    "product": "com.palantir.workspace:workspace",
    "versions": [
      {
        "version": "*",
        "versionType": "semver",
        "lessThan": "7.7.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

17.7%

Related for CVELIST:CVE-2023-30955