PT-2022-18670 · Palantir · Palantir Foundry Multipass
Published
2022-06-14
·
Updated
2022-06-23
·
CVE-2022-27889
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Palantir Foundry Multipass versions prior to 3.647.0
Description
The Multipass service has code paths that can be exploited to cause a denial of service for authentication or authorization operations. A malicious attacker can perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail, leading to performance degradation or login failures for customer Palantir Foundry environments.
Recommendations
For versions prior to 3.647.0, update to Multipass 3.647.0 to resolve the issue. As a temporary workaround, consider restricting access to authentication and authorization operations to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Palantir Foundry Multipass