CVE-2023-22834

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/06/2023
Last modified:
07/11/2023

Description

The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:palantir:contour:*:*:*:*:*:*:*:* 9.642.0 (excluding)