« Volver al listado

CVE-2023-30968

Estado: AplazadaMedia (6.8)—

One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-30968",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-30968",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-21T15:33:22.486616Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@palantir.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@palantir.com",
      "affectedData": [
        {
          "vendor": "Palantir",
          "product": "com.palantir.acme.gaia:gaia",
          "versions": [
            {
              "status": "unaffected",
              "version": "100.240108.11",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "100.240203.6",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "100.230807.13",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "100.240205.0-12-gf415217",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "100.231108.82",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "100.231009.47",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "100.240202.9",
              "lessThan": "*",
              "versionType": "semver"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-03-12T20:15:07.347",
  "references": [
    {
      "url": "https://palantir.safebase.us/?tcuUid=01589957-ed41-4c74-90a0-3f09f7aee1cb",
      "source": "cve-coordination@palantir.com"
    },
    {
      "url": "https://palantir.safebase.us/?tcuUid=01589957-ed41-4c74-90a0-3f09f7aee1cb",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@palantir.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.\n"
    },
    {
      "lang": "es",
      "value": "Se descubrió que uno de los servicios de Gotham Gaia era afectado por una vulnerabilidad de Cross Site Scripting (XSS) almacenadas que podría haber permitido a un atacante eludir CSP y obtener un payload persistente de Cross Site Scripting en la pila."
    }
  ],
  "lastModified": "2026-06-17T05:56:00.547",
  "sourceIdentifier": "cve-coordination@palantir.com"
}