Gotham Gaia Services Vulnerable to Stored XSS
CVE-2023-30968
6.8MEDIUM
What is CVE-2023-30968?
A vulnerability exists within Gotham Gaia services that enables an attacker to inject a persistent cross-site scripting (XSS) payload. This stored XSS vulnerability bypasses Content Security Policy (CSP) protections, potentially compromising the security of applications and their users. Exploitation of this flaw could allow malicious actors to execute scripts within the context of users' sessions, leading to unauthorized actions and data exfiltration.
Affected Version(s)
com.palantir.acme.gaia:gaia 100.240108.11
com.palantir.acme.gaia:gaia 100.240203.6
com.palantir.acme.gaia:gaia 100.230807.13