支持本站 — 捐款将帮助我们持续运营

目标: 1000 元,已筹: 1000

100.0%
获取后续新漏洞提醒登录后订阅
一、 漏洞 CVE-2025-62487 基础信息
漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings of their parent artifact. This lack of security markings could lead to unintended access to the uploaded files.
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked correctly with the proper security levels. The regression was traced back to a change in May 2025, which was meant to allow file uploads to be shared among different artifacts (e.g. other dossiers and presentations). On deployments configured with CBAC, the front-end would present a security picker dialog to set the security level on the uploads, thereby mitigating the issue. On deployments without a CBAC configuration, no security picker dialog appears, leading to a security level of CUSTOM with no markings or datasets selected. The resulting markings and groups for the file uploads thus will be only those added by the default authorization rules defined in the Auth Chooser configuration. On most environments, it is expected that the default authorization rules only add the Everyone group.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
授权机制不正确
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Palantir Gotham和Palantir Dossier 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Palantir Gotham和Palantir Dossier都是美国Palantir公司的产品。Palantir Gotham是一款可商用、支持人工智能的操作系统。Palantir Dossier是一个写作调查和动态报告工具。 Palantir Gotham和Palantir Dossier存在安全漏洞,该漏洞源于上传的图像未正确标记安全级别,可能导致文件仅添加Everyone组。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD
受影响产品
厂商产品影响版本CPE订阅
Palantircom.palantir.acme:gotham-default-apps-bundle 100.30251002.0 ~ * -
Palantircom.palantir.acme:stencil-app-bundle 100.30250907.11 -
Palantircom.palantir.acme:dossier-app 100.30250907.11 -
二、漏洞 CVE-2025-62487 的公开POC
#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC
三、漏洞 CVE-2025-62487 的情报信息
Please 登录 to view more intelligence information
四、漏洞 CVE-2025-62487 的评论

暂无评论


发表评论