Unauthorized Access to Restricted Data in Palantir Foundry
CVE-2024-49589
6.5MEDIUM
What is CVE-2024-49589?
An identified software bug in Palantir Foundry's Object Explorer component allowed users without the necessary permissions to bypass restrictions on viewing certain objects. This issue arose under specific conditions, although it did not permit any unauthorized data access across different organizational boundaries or to unauthenticated users. Palantir has swiftly addressed this vulnerability with a patch that has been automatically deployed to all instances managed by Apollo, ensuring user data remains secure.
Affected Version(s)
com.palantir.artifacts:artifacts * < 0.1337.0