VYPR
Critical severity9.8NVD Advisory· Published Jun 26, 2023· Updated Jun 17, 2026

CVE-2023-30945

CVE-2023-30945

Description

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • Palace/VHSllm-create
  • Palace/VCDllm-create
  • Palace/Clips2llm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • cpe:2.3:a:palantir:clips2:*:*:*:*:*:*:*:*range: <0.111.2
  • Palace/Video Clip Distributorcpe-rescue2 versions
    *+ 1 more
    • (no CPE)range: *
    • cpe:2.3:a:palantir:video_clip_distributor:*:*:*:*:*:*:*:*range: <0.24.10
  • Palantir/com.palantir.gotham:clips2v5
    Range: *
  • Palantir/com.palantir.video:video-history-serverv5
    Range: *
  • cpe:2.3:a:palantir:video_history_service:*:*:*:*:*:*:*:*
    Range: <2.210.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.