Vulnerabilities in Palantir

47 results
Vexday analysis

Palantir apresenta 47 vulnerabilidades cadastradas, sendo 3 críticas, mas nenhuma sob exploração ativa conhecida (KEV). A fraqueza predominante é validação inadequada de entrada (CWE-20), típica de falhas de sanitização. Sem publicações recentes (últimos 90 dias), o risco é estável e não apresenta urgência imediata de mitigação.

CVE-2023-30969HIGHPalantir Tiles missing authentication on API endpointsEPSS 0.4%CVE-2023-30955MEDIUMFoundry workspace-server Developer Mode Authorization BypassEPSS 0.4%CVE-2022-27896MEDIUMThe Foundry Code-Workbooks service was found to contain an issue leading to information disclosure.EPSS 0.4%CVE-2022-27895MEDIUMA component in Foundry logging was found to be capturing sensitive information in logs.EPSS 0.4%CVE-2024-49581MEDIUMAccess control issue impacting RV backed objectsEPSS 0.4%CVE-2025-68609MEDIUMAuthentication bypass in Aries due to misconfigurationEPSS 0.4%CVE-2023-30961MEDIUMPalantir Gotham UI bug that could lead to incorrect data classificationEPSS 0.4%CVE-2023-22834LOWThe contour service was not checking that users had permission to create an analysis for a given datasetEPSS 0.4%CVE-2022-27894MEDIUMThe Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability.EPSS 0.3%CVE-2023-30962MEDIUMStored XSS in cerberus attachmentsEPSS 0.3%CVE-2023-30959MEDIUMStored XSS via javascript URI in Apollo Change Requests commentEPSS 0.3%CVE-2023-30954LOWGotham Video Broken AuthenticationEPSS 0.3%CVE-2024-49587CRITICALGlutton V1 endpoints missing authenticationEPSS 0.3%CVE-2024-49588MEDIUMMultiple authenticated SQL injections in oracle-sidecarEPSS 0.3%CVE-2023-22836LOWIn cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes the linter name from the default value, the renamed value may be visible to the rest of the stack’s tenants.EPSS 0.3%CVE-2022-48306MEDIUMGotham Chat IRC help does not validate hostnames in TLS certificatesEPSS 0.3%CVE-2025-53710HIGHNetwork boundaries not respected in certain Foundry namespaces.EPSS 0.2%CVE-2022-27888MEDIUMThe Foundry Issues service was found to be logging in a manner that captured session tokens.EPSS 0.2%CVE-2022-27890MEDIUMIt was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactoryEPSS 0.2%CVE-2022-48307MEDIUMIt was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactorEPSS 0.2%