Vulnerabilities in Palantir
47 resultsVexday analysis
Palantir apresenta 47 vulnerabilidades cadastradas, sendo 3 críticas, mas nenhuma sob exploração ativa conhecida (KEV). A fraqueza predominante é validação inadequada de entrada (CWE-20), típica de falhas de sanitização. Sem publicações recentes (últimos 90 dias), o risco é estável e não apresenta urgência imediata de mitigação.
CVE-2025-62487LOWUnder certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings of their parent artifact. This lack of security markings could lead to unintended access to the uploaded files.EPSS 0.2%CVE-2023-30971MEDIUMGaia unauthenticated endpointsEPSS 0.2%CVE-2023-30949MEDIUMCVE-2023-30949EPSS 0.2%CVE-2022-27893MEDIUMThe Foundry Magritte plugin osisoft-pi-web-connector was found to be logging in a manner that captured authentication requests.EPSS 0.2%CVE-2022-48308MEDIUMIt was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactoryEPSS 0.2%CVE-2025-64400MEDIUMInsufficient permission checks when pre-enrolling users SummaryEPSS 0.2%CVE-2025-53709MEDIUMAccess control issues impacting secure-upload serviceEPSS 0.2%