The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://palantir.safebase.us/?tcuUid=92dd599a-07e2-43a8-956a-9c9566794be0 | vendor advisory |