Palantir是美国Palantir公司的一个数据平台,通过消除后端数据管理和前端数据分析之间的障碍来重新构想人们如何使用数据。 Palantir Gotham 3.22.11.2之前版本存在安全漏洞,该漏洞源于包含一个未经身份验证的端点,该端点允许攻击者耗尽 Gotham 调度服务的内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-27890 | 6.3 MEDIUM | Palantir 信任管理问题漏洞 |
| CVE-2022-48307 | 6.3 MEDIUM | Palantir 信任管理问题漏洞 |
| CVE-2022-48308 | 6.3 MEDIUM | Palantir 信任管理问题漏洞 |
| CVE-2022-48306 | 5.7 MEDIUM | Gotham Chat IRC help does not validate hostnames in TLS certificates |
| CVE-2022-27891 | 5.3 MEDIUM | Palantir Gotham included an unauthenticated endpoint that listed all active usernames in t |
| CVE-2022-27897 | 5.3 MEDIUM | Palantir Gotham included an endpoint that would log arbitrary sized zip files. |
No comments yet