CVE Vulnerabilities

CVE-2023-30949

Improper Use of Validation Framework

Published: Jul 26, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the pages content, which could lead to phishing attacks.

Weakness

The product does not use, or incorrectly uses, an input validation framework that is provided by the source language or an independent library.

Affected Software

Name Vendor Start Version End Version
Slate Palantir * 6.207.0 (excluding)

Potential Mitigations

References