PT-2022-18670 · Palantir · Palantir Foundry Multipass

Published

2022-06-14

·

Updated

2022-06-23

·

CVE-2022-27889

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palantir Foundry Multipass versions prior to 3.647.0
Description The Multipass service has code paths that can be exploited to cause a denial of service for authentication or authorization operations. A malicious attacker can perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail, leading to performance degradation or login failures for customer Palantir Foundry environments.
Recommendations For versions prior to 3.647.0, update to Multipass 3.647.0 to resolve the issue. As a temporary workaround, consider restricting access to authentication and authorization operations to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27889

Affected Products

Palantir Foundry Multipass