First published: Mon Jul 10 2023(Updated: )
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required.
Credit: cve-coordination@palantir.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palantir Foundry | <4.645.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30960 is a security defect in Foundry job-tracker that allowed users to query metadata related to builds on resources they didn't have access to.
CVE-2023-30960 has a severity level of medium.
To fix CVE-2023-30960, you need to update your Foundry job-tracker to version 4.645.0 or higher.
The affected software for CVE-2023-30960 is Palantir Foundry Job-tracker version up to 4.645.0.