PT-2023-15684 · Palantir · Palantir Gotham Chat Irc Helper
Published
2023-02-16
·
Updated
2023-02-27
·
CVE-2022-48306
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242
Description
The issue is related to improper validation of certificates with host mismatch, allowing a malicious attacker in a privileged network position to perform a man-in-the-middle attack. This could enable them to intercept, read, or modify network communications to and from the affected service.
Recommendations
For versions prior to 30221005.210011.9242, update to a version that includes the fix for this issue to prevent man-in-the-middle attacks. As a temporary workaround, consider restricting network access to the Palantir Gotham Chat IRC helper until a patch is available.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Palantir Gotham Chat Irc Helper