First published: Mon Jun 26 2023(Updated: )
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.
Credit: cve-coordination@palantir.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palantir Clips2 | <0.111.2 | |
Palantir Video Clip Distributor | <0.24.10 | |
Palantir Video History Service | <2.210.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30945 is a vulnerability that affects multiple services such as VHS (Video History Server), VCD (Video Clip Distributor), and Clips2. It allows an unauthenticated attacker to read and write arbitrary files due to missing input validation on filenames.
CVE-2023-30945 affects Palantir Clips2, Palantir Video Clip Distributor, and Palantir Video History Service.
CVE-2023-30945 has a severity level of critical with a CVSS score of 9.8.
An attacker can exploit CVE-2023-30945 by sending requests with crafted filenames to the vulnerable services, allowing them to read and write arbitrary files.
To fix CVE-2023-30945, it is recommended to update the affected software versions to the patched releases provided by Palantir.