The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://palantir.safebase.us/?tcuUid=d839709d-c50f-4a37-8faa-b0c35054418a | mitigation vendor advisory |