Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gotham Blackbird Witchcraft MEDIUM 6.5
CVE-2023-30970

Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on …

Fix: 1.1.0 / 103.30230304.433+
Fix from $1,600 2024-01-29
Orbital Simulator HIGH 7.5
CVE-2023-30967

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbit…

Fix: 0.692.0+
Fix from $1,950 2023-10-26
Tiles MEDIUM 6.5
CVE-2023-30969

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all…

Fix: 4.326.0+
Fix from $1,600 2023-10-26
Gotham Fe Bundle MEDIUM 6.1
CVE-2023-30961

Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to…

Fix: 100.30230704.15 / 100.30230706.20+
Fix from $1,600 2023-09-27
Apollo Autopilot MEDIUM 5.4
CVE-2023-30959

In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user in…

Fix: 3.308.0+
Fix from $1,600 2023-09-27
Gotham Cerberus MEDIUM 5.4
CVE-2023-30962

The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Go…

Fix: 100.230704.0-27-g031dd58+
Fix from $1,600 2023-09-12
Magritte Rest Source Bundle MEDIUM 6.5
CVE-2023-30951

The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).

Fix: 7.210.0+
Fix from $1,600 2023-08-03
Foundry Campaigns MEDIUM 5.9
CVE-2023-30950

The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint

Fix: 0.623.0+
Fix from $1,600 2023-08-03
Slate MEDIUM 5.3
CVE-2023-30949

A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attack…

Fix: 6.207.0+
Fix from $1,600 2023-07-26
Foundry Frontend MEDIUM 5.4
CVE-2023-30963

A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed.…

Fix: 6.229.0+
Fix from $1,600 2023-07-10
Foundry Comments MEDIUM 5.3
CVE-2023-30956

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if th…

Fix: 2.267.0+
Fix from $1,600 2023-07-10
Foundry Frontend HIGH 7.7
CVE-2023-22835

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue…

Fix: 2.510.0 / 6.228.0+
Fix from $1,950 2023-07-10
Foundry Workspace Server MEDIUM 5.4
CVE-2023-30955

A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Devel…

Fix: 7.7.0+
Fix from $1,600 2023-06-29
Clips2 CRITICAL 9.8
CVE-2023-30945

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated…

Fix: 0.24.10 / 0.111.2+
Fix from $2,300 2023-06-26
Foundry MEDIUM 6.5
CVE-2023-22833

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Found…

Fix: after 2.531.0
Fix from $1,600 2023-06-06
Foundry Comments MEDIUM 6.5
CVE-2023-30948

A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorizatio…

Fix: 2.249.0+
Fix from $1,600 2023-06-06
Gotham HIGH 7.5
CVE-2022-27892

Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Got…

Fix: 3.22.11.2+
Fix from $1,950 2023-02-16
Gotham HIGH 7.5
CVE-2022-27897

Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory.…

Fix: 3.22.11.2+
Fix from $1,950 2023-02-16
Gotham Chat Irc MEDIUM 6.8
CVE-2022-48306

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a pri…

Fix: 30221005.210011.9242+
Fix from $1,600 2023-02-16
Gotham MEDIUM 5.3
CVE-2022-27891

Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have…

Fix: 3.22.10.4+
Fix from $1,600 2023-02-16
Atlasdb HIGH 7.4
CVE-2022-27890

It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A m…

Fix: 0.730.0+
Fix from $1,950 2023-02-16
Foundry Build2 HIGH 7.5
CVE-2022-27895

Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This …

Fix: 1.785.0+
Fix from $1,950 2022-11-15
Foundry Code Workbooks HIGH 7.5
CVE-2022-27896

Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating serv…

Fix: 4.461.0+
Fix from $1,950 2022-11-14
Foundry Blobster MEDIUM 5.4
CVE-2022-27894

The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Foundry …

Fix: 3.227.0+
Fix from $1,600 2022-11-04
Foundry Multipass CRITICAL 9.1
CVE-2022-27889

The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. …

Fix: 3.647.0+
Fix from $2,300 2022-06-14
Foundry Issues MEDIUM 5.5
CVE-2022-27888

Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This iss…

Fix: 2.249.1+
Fix from $1,600 2022-04-26