Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NPalantir Gotham Blackbird Witchcraft
APPPalantir10.1 – 104.30231001.8 (excl.)10.2 – 104.30231002.10 (excl.)10.3 – 104.30231003.9 (excl.)9.8 – 104.30230908.21 (excl.)8.7 – 104.30230807.59 (excl.)6.4 – 104.30230604.81 (excl.)3.4 – 103.30230304.433 (excl.)Palantir Gotham Static Assets Servlet
APPPalantir< 1.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
Related vulnerabilities
CVE-2023-30967CRITICAL9.8PL ✓same vendor
Path Traversal w Palantir Gotham Orbital-Simulator — nieautoryzowany odczyt plików
CVE-2023-30945CRITICAL9.8PL ✓same vendor
Nieuwierzytelniony odczyt/zapis plików w Palantir VHS, VCD i Clips2
CVE-2023-30969HIGH8.2same vendor
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not perform...
CVE-2023-22835HIGH7.7same vendor
A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack b...
CVE-2023-22833HIGH7.6same vendor
Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that all...