CVE-2023-30968: Palantir Com.palantir.acme.gaia:gaia

Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.

One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.

Affected products

Published 2024-03-12. Last modified 2026-06-17.