CVE-2023-30959: Stored XSS via javascript URI in Apollo Change Requests comment
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30959?
CVE-2023-30959 is a vulnerability in Apollo change requests that allows users to add comments with a JavaScript URI link, resulting in an XSS attack.
How severe is CVE-2023-30959?
CVE-2023-30959 has a severity rating of 5.4, which is considered medium.
What software is affected by CVE-2023-30959?
The Palantir Apollo Autopilot software version up to 3.308.0 is affected by CVE-2023-30959.
How can I fix CVE-2023-30959?
To fix CVE-2023-30959, it is recommended to update Palantir Apollo Autopilot to a version that includes a patch for the vulnerability.
What is the Common Weakness Enumeration (CWE) for CVE-2023-30959?
The Common Weakness Enumeration (CWE) for CVE-2023-30959 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').