First published: Tue Apr 26 2022(Updated: )
Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.
Credit: cve-coordination@palantir.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palantir Foundry | >=2.244.0<2.249.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-27888 is medium with a severity value of 5.5.
The Foundry Issues service versions 2.244.0 to 2.249.0 are affected by CVE-2022-27888.
CVE-2022-27888 captured sensitive information, specifically session tokens.
CVE-2022-27888 was fixed in version 2.249.1 of the Foundry Issues service.
You can find more information about CVE-2022-27888 in the Palantir security bulletin: https://github.com/palantir/security-bulletins/blob/main/PLTRSEC-2022-01.md