nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-30958 CVE-2023-30958
MEDIUM
DOM XSS in Developer mode dashboard via redirect GET parameter
Record summary
CVE-2023-30958 has a selected CVSS score of 4.7 (medium).
Description
A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
com.palantir.foundry:foundry-frontendBrowse Palantir / com.palantir.foundry:foundry-frontend | CVE List | * to < 6.225.0 | affected |
References
2palantir.safebase.us
https://palantir.safebase.us/?tcuUid=5764b094-d3c0-4380-90f2-234f36116c9b