Vulnerability Details CVE-2023-30945
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-30945
-
cpe:2.3:a:palantir:clips2:*
-
cpe:2.3:a:palantir:video_clip_distributor:*
-
cpe:2.3:a:palantir:video_history_service:*