CVE-2023-22833

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.
Configurations

Configuration 1 (hide)

cpe:2.3:a:palantir:foundry:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 7.6
References () https://palantir.safebase.us/?tcuUid=7f1fd834-805d-4679-85d0-9d779fa064ae - Vendor Advisory () https://palantir.safebase.us/?tcuUid=7f1fd834-805d-4679-85d0-9d779fa064ae - Vendor Advisory

16 Jun 2023, 18:04

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Palantir
Palantir foundry
CWE CWE-863
References (MISC) https://palantir.safebase.us/?tcuUid=7f1fd834-805d-4679-85d0-9d779fa064ae - (MISC) https://palantir.safebase.us/?tcuUid=7f1fd834-805d-4679-85d0-9d779fa064ae - Vendor Advisory
CPE cpe:2.3:a:palantir:foundry:*:*:*:*:*:*:*:*

08 Jun 2023, 17:15

Type Values Removed Values Added
Summary Palantir discovered a software bug in a recently released version of Foundry’s Lime2 service, one of the services backing the Ontology. The software bug has been fixed and the fix has been deployed to your hosted Foundry environment. The vulnerability allowed authenticated users within a Foundry organization to potentially bypass discretionary or mandatory access controls under certain circumstances. Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.

06 Jun 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-06 19:15

Updated : 2024-11-21 07:45


NVD link : CVE-2023-22833

Mitre link : CVE-2023-22833

CVE.ORG link : CVE-2023-22833


JSON object : View

Products Affected

palantir

  • foundry
CWE
CWE-304

Missing Critical Step in Authentication

CWE-863

Incorrect Authorization