Vulnerabilities
Vulnerable Software
Palantir:  Security Vulnerabilities
The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Foundry to launch attacks against other users. This vulnerability is resolved in Blobster 3.228.0.
CVSS Score
4.8
EPSS Score
0.001
Published
2022-11-04
The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail for the duration of the attack. This could lead to performance degradation or login failures for customer Palantir Foundry environments. This vulnerability is resolved in Multipass 3.647.0. This issue affects: Palantir Foundry Multipass versions prior to 3.647.0.
CVSS Score
5.3
EPSS Score
0.004
Published
2022-06-14
Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-04-26


Contact Us

Shodan ® - All rights reserved