« Volver al listado

CVE-2023-30945

Estado: ModificadaCrítica (9.8)—

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-30945",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-30945",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-05T14:30:00.403117Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@palantir.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@palantir.com",
      "affectedData": [
        {
          "vendor": "Palantir",
          "product": "com.palantir.gotham:clips2",
          "versions": [
            {
              "status": "affected",
              "version": "*",
              "lessThan": "0.111.2",
              "versionType": "semver"
            }
          ]
        },
        {
          "vendor": "Palantir",
          "product": "com.palantir.video:video-history-server",
          "versions": [
            {
              "status": "affected",
              "version": "*",
              "lessThan": "2.210.3",
              "versionType": "semver"
            }
          ]
        },
        {
          "vendor": "Palantir",
          "product": "com.palantir.video:video-clip-distributor",
          "versions": [
            {
              "status": "affected",
              "version": "*",
              "lessThan": "0.24.10",
              "versionType": "semver"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-06-26T23:15:09.193",
  "references": [
    {
      "url": "https://palantir.safebase.us/?tcuUid=e62e4dad-b39b-48ba-ba30-7b7c83406ad9",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-coordination@palantir.com"
    },
    {
      "url": "https://palantir.safebase.us/?tcuUid=e62e4dad-b39b-48ba-ba30-7b7c83406ad9",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@palantir.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        },
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well."
    }
  ],
  "lastModified": "2026-06-17T05:55:57.753",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:palantir:clips2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB9EB1C8-6DDE-4EC8-99F2-1130EABA72CA",
              "versionEndExcluding": "0.111.2"
            },
            {
              "criteria": "cpe:2.3:a:palantir:video_clip_distributor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4883F5A-B29C-4EB9-9F55-D15499EC1A40",
              "versionEndExcluding": "0.24.10"
            },
            {
              "criteria": "cpe:2.3:a:palantir:video_history_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9C66728-D88D-4A48-89E3-D887A31C78DF",
              "versionEndExcluding": "2.210.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@palantir.com"
}