CVE-2023-30954: Gotham Video Broken Authentication
Published Nov 15, 2023
·Updated
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized.
Affected Software
1 affected component
Palantir Video-application-server<2.206.1
Event History
Nov 15, 2023
CVE Published
07:43 PM
Data Sourced
07:43 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-30954?
The severity of CVE-2023-30954 is low.
2
What is the vulnerability in CVE-2023-30954?
The vulnerability in CVE-2023-30954 is a race condition in the Gotham video-application-server service.
3
How does CVE-2023-30954 affect Palantir Video-application-server?
CVE-2023-30954 affects Palantir Video-application-server version up to 2.206.1.
4
What is the CWE of CVE-2023-30954?
The CWE of CVE-2023-30954 is CWE-362 and CWE-285.
5
Is there a reference for CVE-2023-30954?
Yes, you can find the reference for CVE-2023-30954 [here](https://palantir.safebase.us/?tcuUid=d2366a3e-a92c-476e-8a7a-7db60e4be567).