漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings of their parent artifact. This lack of security markings could lead to unintended access to the uploaded files.
Vulnerability Description
On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked correctly with the proper security levels. The regression was traced back to a change in May 2025, which was meant to allow file uploads to be shared among different artifacts (e.g. other dossiers and presentations). On deployments configured with CBAC, the front-end would present a security picker dialog to set the security level on the uploads, thereby mitigating the issue. On deployments without a CBAC configuration, no security picker dialog appears, leading to a security level of CUSTOM with no markings or datasets selected. The resulting markings and groups for the file uploads thus will be only those added by the default authorization rules defined in the Auth Chooser configuration. On most environments, it is expected that the default authorization rules only add the Everyone group.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Palantir Gotham和Palantir Dossier 安全漏洞
Vulnerability Description
Palantir Gotham和Palantir Dossier都是美国Palantir公司的产品。Palantir Gotham是一款可商用、支持人工智能的操作系统。Palantir Dossier是一个写作调查和动态报告工具。 Palantir Gotham和Palantir Dossier存在安全漏洞,该漏洞源于上传的图像未正确标记安全级别,可能导致文件仅添加Everyone组。
CVSS Information
N/A
Vulnerability Type
N/A