CVE-2023-22834: The contour service was not checking that users had permission to create an analysis for a given dataset
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22834?
CVE-2023-22834 is a vulnerability in the Contour Service that allows an attacker to clutter up Compass folders with unauthorized analyses.
What is the severity of CVE-2023-22834?
CVE-2023-22834 is considered to be a medium severity vulnerability with a CVSS score of 4.3.
How does CVE-2023-22834 impact Palantir Contour?
CVE-2023-22834 affects Palantir Contour versions up to 9.642.0, allowing unauthorized creation of analyses in Compass folders.
How can an attacker exploit CVE-2023-22834?
An attacker can exploit CVE-2023-22834 by creating extraneous analyses in Compass folders for which they do not have permission.
Is there a fix available for CVE-2023-22834?
To fix CVE-2023-22834, it is recommended to update Palantir Contour to a version that includes the necessary security patches.