CVE-2023-30956

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jul 10, 2023
Updated: Nov 7, 2023
CWE ID 639

Summary

CVE-2023-30956 refers to a vulnerability in Foundry Comments, where a user could discover the contents of an attachment submitted to another comment by knowing the internal UUID of the target attachment. This security issue was resolved with the release of Foundry Comments 2.267.0. The flaw posed a risk to confidentiality as unauthorized users could potentially gain access to sensitive information contained in attachments. The vulnerability did not allow for arbitrary file reading or downloading but rather relied on the attacker having knowledge of a specific attachment UUID. Users are advised to update their Foundry Comments installation to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-30956 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions