HIGH🇬🇧 English

CVE-2023-22835

CVSS 7.7v3.1pub. 2023-07-10upd. 2024-11-21

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue that caused loss of frontend functionality to all issue participants. This defect was resolved with the release of Foundry Issues 2.510.0 and Foundry Frontend 6.228.0.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
  • Palantir Foundry Frontend

    APP
    Palantir
    < 6.228.0
  • Palantir Foundry Issues

    APP
    Palantir
    < 2.510.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoS
CWE
Referencje

Powiązane podatności

CVE-2023-30963MEDIUM5.4ten sam produkt

A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slat...

CVE-2022-27888MEDIUM5.5ten sam produkt

Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive...

CVE-2023-30946LOW3.5ten sam produkt

Odkryto lukę bezpieczeństwa w Foundry Issues. Jeśli użytkownik został dodany do problemu dotyczącego zasobu, d...

CVE-2023-30967CRITICAL9.8PL ✓ten sam vendor

Path Traversal w Palantir Gotham Orbital-Simulator — nieautoryzowany odczyt plików

CVE-2023-30945CRITICAL9.8PL ✓ten sam vendor

Nieuwierzytelniony odczyt/zapis plików w Palantir VHS, VCD i Clips2