CVE-2022-27897: Palantir Gotham included an endpoint that would log arbitrary sized zip files.
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly upload a malicious zip file, which would allow them to exhaust memory resources on the dispatch server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27897?
CVE-2022-27897 is a vulnerability in Palantir Gotham versions prior to 3.22.11.2 that allows an attacker to exhaust memory resources on the dispatch server.
How severe is CVE-2022-27897?
CVE-2022-27897 has a severity rating of 7.5 (high).
What is affected by CVE-2022-27897?
Palantir Gotham versions prior to 3.22.11.2 are affected by CVE-2022-27897.
How can an attacker exploit CVE-2022-27897?
An attacker can repeatedly upload a malicious zip file to exhaust memory resources on the dispatch server.
Is there a fix for CVE-2022-27897?
Yes, upgrading to Palantir Gotham version 3.22.11.2 or later fixes CVE-2022-27897.