CVE-2023-30968: Palantir Com.palantir.acme.gaia:gaia
Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.
One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.
Affected products
- Palantir Com.palantir.acme.gaia:gaia
Published 2024-03-12. Last modified 2026-06-17.