U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-49589

Change History

CVE Modified by Palantir Technologies 2/18/2025 2:15:17 PM

Action Type Old Value New Value
Changed Description
Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users.  
The affected service have been patched and automatically deployed to all Apollo-managed Foundry instances.
Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied argument (size).
Added CVSS V3.1

								
							
							
						
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Removed CVSS V3.1
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

								
						
Added CWE

								
							
							
						
CWE-770
Removed CWE
CWE-862

								
						
Added Reference

								
							
							
						
https://palantir.safebase.us/?tcuUid=ad6b08b1-2f79-4e32-b125-406dd2b9b1c3
Removed Reference
https://palantir.safebase.us/?tcuUid=b60db1ee-4b1a-475d-848e-c5a670a0da16