Metrics
Affected Vendors & Products
Tue, 18 Feb 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-862 | |
References |
|
Tue, 18 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-862 | |
References |
|
Tue, 18 Feb 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users. The affected service have been patched and automatically deployed to all Apollo-managed Foundry instances. | Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied argument (size). |
Title | Access control issue impacting RV backed objects | Foundry artifacts denial of service |
Weaknesses | CWE-862 | CWE-770 |
References | ||
Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 18 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 18 Feb 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users. The affected service have been patched and automatically deployed to all Apollo-managed Foundry instances. | |
Title | Access control issue impacting RV backed objects | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Palantir
Published: 2025-02-18T17:18:41.883Z
Updated: 2025-02-18T18:11:28.932Z
Reserved: 2024-10-16T19:09:45.689Z
Link: CVE-2024-49589

Updated: 2025-02-18T17:25:35.665Z

Status : Awaiting Analysis
Published: 2025-02-18T18:15:25.300
Modified: 2025-02-18T19:15:17.670
Link: CVE-2024-49589

No data.