CVE-2023-30960: Insecure Direct Object Reference (IDOR) in Foundry job-tracker
Published Jul 10, 2023
·Updated
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required.
Affected Software
1 affected component
Palantir Foundry Job-tracker<4.645.0
Event History
Jul 10, 2023
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-30960?
CVE-2023-30960 is a security defect in Foundry job-tracker that allowed users to query metadata related to builds on resources they didn't have access to.
2
How severe is CVE-2023-30960?
CVE-2023-30960 has a severity level of medium.
3
How do I fix CVE-2023-30960?
To fix CVE-2023-30960, you need to update your Foundry job-tracker to version 4.645.0 or higher.
4
What is the affected software for CVE-2023-30960?
The affected software for CVE-2023-30960 is Palantir Foundry Job-tracker version up to 4.645.0.