CVE-2023-30949: Medium severity palantir slate vulnerability
Published Jul 26, 2023
·Updated
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.
Affected Software
1 affected component
Palantir Slate<6.207.0
Event History
Jul 26, 2023
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionSeverityWeakness
Data Sourced
06:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-30949.
2
What is the severity of CVE-2023-30949?
The severity of CVE-2023-30949 is medium with a CVSS score of 5.3.
3
What is the affected software for CVE-2023-30949?
The affected software for CVE-2023-30949 is Palantir Slate with versions up to and excluding 6.207.0.
4
How can a malicious user exploit CVE-2023-30949?
A malicious user can exploit CVE-2023-30949 by taking advantage of a missing origin validation in Slate sandbox to modify the page's content, potentially leading to phishing attacks.
5
Is there a fix available for CVE-2023-30949?
Yes, it is recommended to update to a version of Palantir Slate that is newer than 6.207.0 to mitigate the vulnerability.