CVE-2023-30945

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
26/06/2023
Last modified:
07/11/2023

Description

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:palantir:clips2:*:*:*:*:*:*:*:* 0.111.2 (excluding)
cpe:2.3:a:palantir:video_clip_distributor:*:*:*:*:*:*:*:* 0.24.10 (excluding)
cpe:2.3:a:palantir:video_history_service:*:*:*:*:*:*:*:* 2.210.3 (excluding)