CVE-2023-30970

Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.

Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
PalantirCNA
6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
palantirgotham_blackbird-witchcraft
10.1 ≤
𝑥
< 104.30231001.8
palantirgotham_blackbird-witchcraft
10.2 ≤
𝑥
< 104.30231002.10
palantirgotham_blackbird-witchcraft
10.3 ≤
𝑥
< 104.30231003.9
palantirgotham_blackbird-witchcraft
9.8 ≤
𝑥
< 104.30230908.21
palantirgotham_blackbird-witchcraft
8.7 ≤
𝑥
< 104.30230807.59
palantirgotham_blackbird-witchcraft
6.4 ≤
𝑥
< 104.30230604.81
palantirgotham_blackbird-witchcraft
3.4 ≤
𝑥
< 103.30230304.433
palantirgotham_static-assets-servlet
𝑥
< 1.1.0
𝑥
= Vulnerable software versions