ZeroHour

CVE-2023-22834

CVSS 3.1
4.3 medium
EPSS
<1%p28
Published
()
Modified
Description

The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.

Vendors
palantir
Products
contour
Weakness
CWE-425, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.