Loading HuntDB...

Palantir

36 Products 18 CVEs

CVE Severity Distribution (All Time)

Critical
0
High
1
Medium
17
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-49588 MEDIUM 1 year ago

Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.

CVE-2023-30968 MEDIUM 1 year, 8 months ago

One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to by…

CVE-2023-30961 MEDIUM 2 years, 1 month ago

Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to…

CVE-2023-30952 MEDIUM 2 years, 3 months ago

A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating a…

CVE-2023-22833 HIGH 2 years, 5 months ago

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Found…

CVE-2022-48308 MEDIUM 2 years, 9 months ago

It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A m…

CVE-2022-48306 MEDIUM 2 years, 9 months ago

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a pri…

CVE-2022-48307 MEDIUM 2 years, 9 months ago

It was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A …

CVE-2022-27897 MEDIUM 2 years, 9 months ago

Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory.…

CVE-2022-27891 MEDIUM 2 years, 9 months ago

Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have…