PT-2023-15684 · Palantir · Palantir Gotham Chat Irc Helper
Publicado
2023-02-16
·
Atualizado
2023-02-27
·
CVE-2022-48306
CVSS v3.1
6.8
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242
Description
The issue is related to improper validation of certificates with host mismatch, allowing a malicious attacker in a privileged network position to perform a man-in-the-middle attack. This could enable them to intercept, read, or modify network communications to and from the affected service.
Recommendations
For versions prior to 30221005.210011.9242, update to a version that includes the fix for this issue to prevent man-in-the-middle attacks. As a temporary workaround, consider restricting network access to the Palantir Gotham Chat IRC helper until a patch is available.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Palantir Gotham Chat Irc Helper