7.5
CVE-2022-27892
- EPSS 0.62%
- Veröffentlicht 16.02.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 06:56:25
- Quelle cve-coordination@palantir.com
- CVE-Watchlists
- Unerledigt
Palantir Gotham included an endpoint that would log arbitrary sized payloads.
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Gotham dispatch service.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.62% | 0.448 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| cve-coordination@palantir.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://github.com/palantir/security-bulletins/blob/main/PLTRSEC-2022-11.md