CVE-2023-22834

The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.
Configurations

Configuration 1 (hide)

cpe:2.3:a:palantir:contour:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 2.7
References () https://palantir.safebase.us/?tcuUid=14874400-e9c9-4ac4-a8a6-9f4c48a56ff8 - Vendor Advisory () https://palantir.safebase.us/?tcuUid=14874400-e9c9-4ac4-a8a6-9f4c48a56ff8 - Vendor Advisory

05 Jul 2023, 19:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
References (MISC) https://palantir.safebase.us/?tcuUid=14874400-e9c9-4ac4-a8a6-9f4c48a56ff8 - (MISC) https://palantir.safebase.us/?tcuUid=14874400-e9c9-4ac4-a8a6-9f4c48a56ff8 - Vendor Advisory
First Time Palantir
Palantir contour
CPE cpe:2.3:a:palantir:contour:*:*:*:*:*:*:*:*
CWE CWE-862

27 Jun 2023, 01:40

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-27 00:15

Updated : 2024-11-21 07:45


NVD link : CVE-2023-22834

Mitre link : CVE-2023-22834

CVE.ORG link : CVE-2023-22834


JSON object : View

Products Affected

palantir

  • contour
CWE
CWE-425

Direct Request ('Forced Browsing')

CWE-862

Missing Authorization