Gotham Gaia Services Vulnerable to Stored XSS
CVE-2023-30968
What is CVE-2023-30968?
A vulnerability exists within Gotham Gaia services that enables an attacker to inject a persistent cross-site scripting (XSS) payload. This stored XSS vulnerability bypasses Content Security Policy (CSP) protections, potentially compromising the security of applications and their users. Exploitation of this flaw could allow malicious actors to execute scripts within the context of users' sessions, leading to unauthorized actions and data exfiltration.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
com.palantir.acme.gaia:gaia 100.240108.11
com.palantir.acme.gaia:gaia 100.240203.6
com.palantir.acme.gaia:gaia 100.230807.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
