First published: Tue Sep 12 2023(Updated: )
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
Credit: cve-coordination@palantir.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palantir Gotham | <100.230704.0-27-g031dd58 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30962 is a stored cross-site scripting (XSS) vulnerability found in the Gotham Cerberus service.
CVE-2023-30962 has a severity rating of 5.4, which is considered medium.
CVE-2023-30962 allows an attacker with access to Gotham to launch cross-site scripting attacks against other users of the service.
To fix CVE-2023-30962, update the Gotham Cerberus service to version 100.230704.0-27-g031dd58 or later.
CVE-2023-30962 is classified under CWE-79, which is the Cross-Site Scripting (XSS) vulnerability category.