Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-49581
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users.
The affected service have been patched and automatically deployed to all Apollo-managed Foundry instances.
0
Attacker Value
Unknown
CVE-2023-30970
Disclosure Date: January 29, 2024 (last updated February 08, 2024)
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
0
Attacker Value
Unknown
CVE-2023-30961
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link.
0
Attacker Value
Unknown
CVE-2023-30962
Disclosure Date: September 12, 2023 (last updated October 08, 2023)
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
0
Attacker Value
Unknown
CVE-2022-48306
Disclosure Date: February 14, 2023 (last updated October 08, 2023)
Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify network communications to and from the affected service. This issue affects: Palantir Palantir Gotham Chat IRC helper versions prior to 30221005.210011.9242.
0
Attacker Value
Unknown
CVE-2022-27891
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham instances. It is highly recommended that customers upgrade all affected services to the latest version. This issue affects: Palantir Gotham versions prior to 103.30221005.0.
0
Attacker Value
Unknown
CVE-2022-27892
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Gotham dispatch service.
0
Attacker Value
Unknown
CVE-2022-27897
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly upload a malicious zip file, which would allow them to exhaust memory resources on the dispatch server.
0