CVE-2023-30959

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
27/09/2023
Last modified:
07/11/2023

Description

In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:palantir:apollo_autopilot:*:*:*:*:*:*:*:* 3.308.0 (excluding)