CVE-2023-22834

The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.
Configurations

Configuration 1 (hide)

cpe:2.3:a:palantir:contour:*:*:*:*:*:*:*:*

History

05 Jul 2023, 19:14

Type Values Removed Values Added
References (MISC) https://palantir.safebase.us/?tcuUid=14874400-e9c9-4ac4-a8a6-9f4c48a56ff8 - (MISC) https://palantir.safebase.us/?tcuUid=14874400-e9c9-4ac4-a8a6-9f4c48a56ff8 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
First Time Palantir
Palantir contour
CWE CWE-862
CPE cpe:2.3:a:palantir:contour:*:*:*:*:*:*:*:*

27 Jun 2023, 01:40

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-27 00:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-22834

Mitre link : CVE-2023-22834

CVE.ORG link : CVE-2023-22834


JSON object : View

Products Affected

palantir

  • contour
CWE
CWE-862

Missing Authorization

CWE-425

Direct Request ('Forced Browsing')