Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown

CVE-2024-49589

Disclosure Date: February 18, 2025 (last updated February 19, 2025)
Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied argument (size).
0
Attacker Value
Unknown

CVE-2024-49581

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users. The affected service have been patched and automatically deployed to all Apollo-managed Foundry instances.
0
Attacker Value
Unknown

CVE-2024-49588

Disclosure Date: November 21, 2024 (last updated January 05, 2025)
Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.
0
Attacker Value
Unknown

CVE-2023-30968

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.
0
Attacker Value
Unknown

CVE-2023-30970

Disclosure Date: January 29, 2024 (last updated February 08, 2024)
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
Attacker Value
Unknown

CVE-2023-30954

Disclosure Date: November 15, 2023 (last updated November 23, 2023)
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized.
Attacker Value
Unknown

CVE-2023-30969

Disclosure Date: October 26, 2023 (last updated November 04, 2023)
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.
Attacker Value
Unknown

CVE-2023-30967

Disclosure Date: October 26, 2023 (last updated November 04, 2023)
Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.
Attacker Value
Unknown

CVE-2023-30961

Disclosure Date: September 27, 2023 (last updated October 08, 2023)
Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link.
Attacker Value
Unknown

CVE-2023-30959

Disclosure Date: September 27, 2023 (last updated October 08, 2023)
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.