Security Advisory

CVE-2023-30945

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-06-26 23:00:08
Last updated 2024-12-05 14:30:12
Assigner Palantir
State PUBLISHED

Description

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.