PT-2023-12923 · Palantir · Palantir Gotham

Published

2023-02-16

·

Updated

2023-02-24

·

CVE-2022-27897

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Palantir Gotham versions prior to 3.22.11.2
Description The issue concerns an unauthenticated endpoint that loads portions of maliciously crafted zip files to memory. An attacker could exploit this by repeatedly uploading a malicious zip file, allowing them to exhaust memory resources on the dispatch server.
Recommendations For Palantir Gotham versions prior to 3.22.11.2, update to version 3.22.11.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the unauthenticated endpoint to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27897

Affected Products

Palantir Gotham