Palantir是美国Palantir公司的一个数据平台,通过消除后端数据管理和前端数据分析之间的障碍来重新构想人们如何使用数据。 Palantir Magritte-ftp 9.466.0之前版本存在安全漏洞,该漏洞源于未验证 TLS 证书中的主机名。攻击者利用该漏洞执行中间人攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palantir | Foundry Magritte | unspecified ~ 9.466.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-27890 | 6.3 MEDIUM | Palantir 信任管理问题漏洞 |
| CVE-2022-48308 | 6.3 MEDIUM | Palantir 信任管理问题漏洞 |
| CVE-2022-48306 | 5.7 MEDIUM | Gotham Chat IRC help does not validate hostnames in TLS certificates |
| CVE-2022-27891 | 5.3 MEDIUM | Palantir Gotham included an unauthenticated endpoint that listed all active usernames in t |
| CVE-2022-27892 | 5.3 MEDIUM | Palantir Gotham included an endpoint that would log arbitrary sized payloads. |
| CVE-2022-27897 | 5.3 MEDIUM | Palantir Gotham included an endpoint that would log arbitrary sized zip files. |
No comments yet