PT-2023-15684 · Palantir · Palantir Gotham Chat Irc Helper

Published

2023-02-16

·

Updated

2023-02-27

·

CVE-2022-48306

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242
Description The issue is related to improper validation of certificates with host mismatch, allowing a malicious attacker in a privileged network position to perform a man-in-the-middle attack. This could enable them to intercept, read, or modify network communications to and from the affected service.
Recommendations For versions prior to 30221005.210011.9242, update to a version that includes the fix for this issue to prevent man-in-the-middle attacks. As a temporary workaround, consider restricting network access to the Palantir Gotham Chat IRC helper until a patch is available.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-48306

Affected Products

Palantir Gotham Chat Irc Helper