CVE-2022-27888: The Foundry Issues service was found to be logging in a manner that captured session tokens.
Published Apr 26, 2022
·Updated
Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.
Affected Software
1 affected component
Palantir Foundry Issues>=2.244.0<2.249.1
Event History
Apr 26, 2022
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-27888?
The severity of CVE-2022-27888 is medium with a severity value of 5.5.
2
Which software versions are affected by CVE-2022-27888?
The Foundry Issues service versions 2.244.0 to 2.249.0 are affected by CVE-2022-27888.
3
What sensitive information was captured by CVE-2022-27888?
CVE-2022-27888 captured sensitive information, specifically session tokens.
4
How was CVE-2022-27888 fixed?
CVE-2022-27888 was fixed in version 2.249.1 of the Foundry Issues service.
5
Where can I find more information about CVE-2022-27888?
You can find more information about CVE-2022-27888 in the Palantir security bulletin: https://github.com/palantir/security-bulletins/blob/main/PLTRSEC-2022-01.md