MEDIUM🇵🇱 Wersja polska

CVE-2022-27888

CVSS 5.5v3.1pub. 2022-04-26upd. 2024-11-21

Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Palantir Foundry Issues

    APP
    Palantir
    2.244.0 – 2.249.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-22835HIGH7.7same product

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack b...

CVE-2023-30946LOW3.5same product

Odkryto lukę bezpieczeństwa w Foundry Issues. Jeśli użytkownik został dodany do problemu dotyczącego zasobu, d...

CVE-2023-30967CRITICAL9.8PL ✓same vendor

Path Traversal w Palantir Gotham Orbital-Simulator — nieautoryzowany odczyt plików

CVE-2023-30945CRITICAL9.8PL ✓same vendor

Nieuwierzytelniony odczyt/zapis plików w Palantir VHS, VCD i Clips2

CVE-2023-30969HIGH8.2same vendor

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not perform...