7.5
CVSSv3

CVE-2022-27897

Published: 16/02/2023 Updated: 24/02/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Palantir Gotham versions before 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly upload a malicious zip file, which would allow them to exhaust memory resources on the dispatch server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

palantir gotham