CVE-2022-27888Log File Information Exposure in Foundry Issues

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 81.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 26
Latest updateApr 28

Description

Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5palantir/foundry_issuesnext of 2.244.0unspecified+1
NVDpalantir/foundry_issues2.244.02.249.1

🔴Vulnerability Details

2
GHSA
GHSA-cwq5-9fp6-j489: Foundry Issues service versions 22022-04-28
CVEList
The Foundry Issues service was found to be logging in a manner that captured session tokens.2022-04-26
CVE-2022-27888 — Log File Information Exposure | cvebase