CVE-2023-30970: Gotham table and Forward App Path traversal
Published Jan 29, 2024
·Updated
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
Affected Software
8 affected components
Palantir Gotham Blackbird-witchcraft>=10.1<104.30231001.8
Palantir Gotham Blackbird-witchcraft>=10.2<104.30231002.10
Palantir Gotham Blackbird-witchcraft>=10.3<104.30231003.9
Palantir Gotham Blackbird-witchcraft>=9.8<104.30230908.21
Palantir Gotham Blackbird-witchcraft>=8.7<104.30230807.59
Palantir Gotham Blackbird-witchcraft>=6.4<104.30230604.81
Palantir Gotham Blackbird-witchcraft>=3.4<103.30230304.433
Palantir Gotham Static-assets-servlet<1.1.0
Event History
Jan 29, 2024
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-30970?
The severity of CVE-2023-30970 is considered high due to its potential impact on sensitive data exposure.
2
How do I fix CVE-2023-30970?
To fix CVE-2023-30970, update Palantir Gotham to a version above 10.4.30231003.9.
3
Who is affected by CVE-2023-30970?
CVE-2023-30970 affects versions of Palantir Gotham between 6.4 and 10.3, as well as Gotham Static Assets Servlet versions below 1.1.0.
4
What kind of attack does CVE-2023-30970 allow?
CVE-2023-30970 allows an authenticated user to perform a path traversal attack, potentially reading arbitrary files on the file system.
5
Is CVE-2023-30970 exploitable without authentication?
No, CVE-2023-30970 requires authentication to exploit the path traversal vulnerability.