First published: Mon Jun 26 2023(Updated: )
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.
Credit: cve-coordination@palantir.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palantir Contour | <9.642.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22834 is a vulnerability in the Contour Service that allows an attacker to clutter up Compass folders with unauthorized analyses.
CVE-2023-22834 is considered to be a medium severity vulnerability with a CVSS score of 4.3.
CVE-2023-22834 affects Palantir Contour versions up to 9.642.0, allowing unauthorized creation of analyses in Compass folders.
An attacker can exploit CVE-2023-22834 by creating extraneous analyses in Compass folders for which they do not have permission.
To fix CVE-2023-22834, it is recommended to update Palantir Contour to a version that includes the necessary security patches.