Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.
The product implements an authentication technique, but it skips a step that weakens the technique.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://palantir.safebase.us/?tcuUid=7f1fd834-805d-4679-85d0-9d779fa064ae | vendor advisory |