{"api_version":"1","generated_at":"2026-04-23T02:37:12+00:00","cve":"CVE-2023-30958","urls":{"html":"https://cve.report/CVE-2023-30958","api":"https://cve.report/api/cve/CVE-2023-30958.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-30958","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-30958"},"summary":{"title":"CVE-2023-30958","description":"A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed.\n\nThis defect was resolved with the release of Foundry Frontend 6.225.0.","state":"PUBLIC","assigner":"cve-coordination@palantir.com","published_at":"2023-08-03 22:15:00","updated_at":"2023-11-07 04:14:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://palantir.safebase.us/?tcuUid=5764b094-d3c0-4380-90f2-234f36116c9b","name":"https://palantir.safebase.us/?tcuUid=5764b094-d3c0-4380-90f2-234f36116c9b","refsource":"MISC","tags":[],"title":"Palantir Trust and Security Portal | SafeBase","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-30958","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30958","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"30958","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zabbix","cpe5":"frontend","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-30958","ASSIGNER":"cve-coordination@palantir.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed.\n\nThis defect was resolved with the release of Foundry Frontend 6.225.0.\n\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"The product does not neutralize or incorrectly neutralizes \"javascript:\" or other URIs from dangerous attributes within tags, such as onmouseover, onload, onerror, or style.","cweId":"CWE-83"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Palantir","product":{"product_data":[{"product_name":"com.palantir.foundry:foundry-frontend","version":{"version_data":[{"version_affected":"<","version_name":"*","version_value":"6.225.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://palantir.safebase.us/?tcuUid=5764b094-d3c0-4380-90f2-234f36116c9b","refsource":"MISC","name":"https://palantir.safebase.us/?tcuUid=5764b094-d3c0-4380-90f2-234f36116c9b"}]},"source":{"discovery":"EXTERNAL","defect":["PLTRSEC-2023-27"]},"impact":{"cvss":[{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","baseSeverity":"MEDIUM","baseScore":4.7}]}},"nvd":{"publishedDate":"2023-08-03 22:15:00","lastModifiedDate":"2023-11-07 04:14:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:*","versionEndExcluding":"6.225.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}