LOW🇬🇧 English

CVE-2023-30946

CVSS 3.5v3.1pub. 2023-06-29upd. 2024-11-21

Odkryto lukę bezpieczeństwa w Foundry Issues. Jeśli użytkownik został dodany do problemu dotyczącego zasobu, do którego nie miał dostępu i nie mógł go widzieć, mógł zapytać Notification API Foundry i otrzymać metadane problemu, w tym RID problemu, poziom ważności, wewnętrzny UUID autora oraz zdefiniowany przez użytkownika tytuł problemu.

Pokaż oryginał (EN)

A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query Foundry's Notification API and receive metadata about the issue including the RID of the issue, severity, internal UUID of the author, and the user-defined title of the issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
  • Palantir Foundry Issues

    APP
    Palantir
    < 2.497.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-22835HIGH7.7ten sam produkt

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack b...

CVE-2022-27888MEDIUM5.5ten sam produkt

Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive...

CVE-2023-30967CRITICAL9.8PL ✓ten sam vendor

Path Traversal w Palantir Gotham Orbital-Simulator — nieautoryzowany odczyt plików

CVE-2023-30945CRITICAL9.8PL ✓ten sam vendor

Nieuwierzytelniony odczyt/zapis plików w Palantir VHS, VCD i Clips2

CVE-2023-30969HIGH8.2ten sam vendor

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not perform...