PT-2023-12921 · Palantir · Palantir Gotham
Published
2023-02-16
·
Updated
2023-07-18
·
CVE-2022-27891
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Palantir Gotham versions prior to 103.30221005.0
Description
The issue concerns an unauthenticated endpoint in Palantir Gotham that lists all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham instances.
Recommendations
For Palantir Gotham versions prior to 103.30221005.0, it is highly recommended that customers upgrade all affected services to the latest version. As a temporary workaround, consider restricting access to the unauthenticated endpoint until the issue is resolved.
Fix
Missing Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Palantir Gotham