Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2024-49589
Disclosure Date: February 18, 2025 (last updated February 19, 2025)
Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied argument (size).
0
Attacker Value
Unknown
CVE-2024-49581
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users.
The affected service have been patched and automatically deployed to all Apollo-managed Foundry instances.
0
Attacker Value
Unknown
CVE-2024-49588
Disclosure Date: November 21, 2024 (last updated January 05, 2025)
Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.
0
Attacker Value
Unknown
CVE-2023-30968
Disclosure Date: March 12, 2024 (last updated April 01, 2024)
One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.
0
Attacker Value
Unknown
CVE-2023-30970
Disclosure Date: January 29, 2024 (last updated February 08, 2024)
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
0
Attacker Value
Unknown
CVE-2023-30954
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized.
0
Attacker Value
Unknown
CVE-2023-30969
Disclosure Date: October 26, 2023 (last updated November 04, 2023)
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.
0
Attacker Value
Unknown
CVE-2023-30967
Disclosure Date: October 26, 2023 (last updated November 04, 2023)
Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.
0
Attacker Value
Unknown
CVE-2023-30961
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link.
0
Attacker Value
Unknown
CVE-2023-30959
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
0