Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NPalantir Foundry Issues
APPPalantir2.244.0 – 2.249.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-22835HIGH7.7same product
A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack b...
CVE-2023-30946LOW3.5same product
Odkryto lukę bezpieczeństwa w Foundry Issues. Jeśli użytkownik został dodany do problemu dotyczącego zasobu, d...
CVE-2023-30967CRITICAL9.8PL ✓same vendor
Path Traversal w Palantir Gotham Orbital-Simulator — nieautoryzowany odczyt plików
CVE-2023-30945CRITICAL9.8PL ✓same vendor
Nieuwierzytelniony odczyt/zapis plików w Palantir VHS, VCD i Clips2
CVE-2023-30969HIGH8.2same vendor
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not perform...