CVE-2022-27889
Summary
| CVE | CVE-2022-27889 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-14 14:15:00 UTC |
| Updated | 2022-06-23 16:22:00 UTC |
| Description | The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail for the duration of the attack. This could lead to performance degradation or login failures for customer Palantir Foundry environments. This vulnerability is resolved in Multipass 3.647.0. This issue affects: Palantir Foundry Multipass versions prior to 3.647.0. |
Risk And Classification
Problem Types: CWE-913
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Palantir | Foundry Multipass | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security-bulletins/PLTRSEC-2022-02.md at main · palantir/security-bulletins · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This issue was identified internally at Palantir. Initial activity was observed as a result of good-faith security research conducted by bug bounty participants.
There are currently no legacy QID mappings associated with this CVE.