Denial of Service in Foundry Issues
CVE-2023-22835

7.7HIGH

Key Information:

What is CVE-2023-22835?

A security defect in Foundry Issues allows users to execute a Denial of Service attack by submitting specially crafted data within an Issue. This flaw can lead to a significant disruption as it causes loss of frontend functionality for all participants in an issue, potentially impacting collaboration and workflow. The issue has been addressed in the latest updates, Foundry Issues 2.510.0 and Foundry Frontend 6.228.0, which mitigate the risk posed by this vulnerability.

Affected Version(s)

com.palantir.foundry:foundry-frontend * < 6.228.0

com.palantir.issues:issues * < 2.510.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-22835 : Denial of Service in Foundry Issues