Vulnerability Details CVE-2022-27897
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly upload a malicious zip file, which would allow them to exhaust memory resources on the dispatch server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.0%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-27897
-
cpe:2.3:o:palantir:gotham:-
-
cpe:2.3:o:palantir:gotham:3.22.10.4