cve/2023/CVE-2023-30955.md
2024-06-18 02:51:15 +02:00

18 lines
1.0 KiB
Markdown

### [CVE-2023-30955](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-30955)
![](https://img.shields.io/static/v1?label=Product&message=com.palantir.workspace%3Aworkspace&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=*%3C%207.7.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=The%20product%20is%20composed%20of%20a%20server%20that%20relies%20on%20the%20client%20to%20implement%20a%20mechanism%20that%20is%20intended%20to%20protect%20the%20server.&color=brighgreen)
### Description
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with workspace-server 7.7.0.
### POC
#### Reference
- https://palantir.safebase.us/?tcuUid=0c3f6c33-4eb0-48b5-ab87-fe48c46a4170
#### Github
No PoCs found on GitHub currently.