Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
The Foundry Issues service was found to be logging in a manner that captured session tokens.
Vulnerability Description
Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
Palantir Foundry Issues 日志信息泄露漏洞
Vulnerability Description
Palantir是美国Palantir公司的一个数据平台,通过消除后端数据管理和前端数据分析之间的障碍来重新构想人们如何使用数据。 Palantir Foundry Issues 服务 2.244.0 到 2.249.0版本存在日志信息泄露漏洞,攻击者可以以捕获敏感信息(会话令牌)的方式登录系统。
CVSS Information
N/A
Vulnerability Type
N/A