Gotham Gaia Services Vulnerable to Stored XSS
CVE-2023-30968
6.8MEDIUM
What is CVE-2023-30968?
A vulnerability exists within Gotham Gaia services that enables an attacker to inject a persistent cross-site scripting (XSS) payload. This stored XSS vulnerability bypasses Content Security Policy (CSP) protections, potentially compromising the security of applications and their users. Exploitation of this flaw could allow malicious actors to execute scripts within the context of users' sessions, leading to unauthorized actions and data exfiltration.
Affected Version(s)
com.palantir.acme.gaia:gaia 100.240108.11
com.palantir.acme.gaia:gaia 100.240203.6
com.palantir.acme.gaia:gaia 100.230807.13
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved