Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on …
Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbit…
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all…
Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to…
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user in…
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Go…
The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).
The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attack…
A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed.…
A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if th…
A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue…
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Devel…
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated…
Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Found…
A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorizatio…
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Got…
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory.…
Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a pri…
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have…
It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A m…
Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This …
Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating serv…
The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Foundry …
The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. …
Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This iss…