CVE-2023-30945

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:palantir:clips2:*:*:*:*:*:*:*:*
cpe:2.3:a:palantir:video_clip_distributor:*:*:*:*:*:*:*:*
cpe:2.3:a:palantir:video_history_service:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-06-26 23:15

Updated : 2023-11-07 04:14


NVD link : CVE-2023-30945

Mitre link : CVE-2023-30945

CVE.ORG link : CVE-2023-30945


JSON object : View

Products Affected

palantir

  • clips2
  • video_clip_distributor
  • video_history_service
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-287

Improper Authentication