CVE-2023-22835Improper Input Validation in Com.palantir.foundry Foundry-frontend

Severity
7.7HIGHNVD
EPSS
0.4%
top 40.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10

Description

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue that caused loss of frontend functionality to all issue participants. This defect was resolved with the release of Foundry Issues 2.510.0 and Foundry Frontend 6.228.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 3.1 | Impact: 4.0

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-cgfq-w4p2-w773: A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue2023-07-10
CVEList
Denial of Service in Foundry Issues2023-07-10
CVE-2023-22835 — Improper Input Validation | cvebase