Skip to main content

Vendor archive

palantir CVEs

Beta · best-effort

33 CVEs tagged to vendor palantir2 Critical, 3 High, 25 Medium, 3 Low, 0 Unrated.

CVE-2023-30969

Published Oct 26, 2023

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30967

Published Oct 26, 2023

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-30959

Published Sep 27, 2023

In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30962

Published Sep 12, 2023

The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30952

Published Aug 3, 2023

A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resol…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30949

Published Jul 26, 2023

A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30963

Published Jul 10, 2023

A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed. This defect was resolved with…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30960

Published Jul 10, 2023

A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30956

Published Jul 10, 2023

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30955

Published Jun 29, 2023

A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30946

Published Jun 29, 2023

A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22834

Published Jun 27, 2023

The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneou…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22833

Published Jun 6, 2023

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass disc…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30948

Published Jun 6, 2023

A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48308

Published Feb 16, 2023

It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A malicious attacker in a privile…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48307

Published Feb 16, 2023

It was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A malicious attacker in a privil…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48306

Published Feb 16, 2023

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27897

Published Feb 16, 2023

Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2