« Back to list

CVE-2024-49581

Status: DeferredMedium (6.5)—

Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users. The affected service have been patched and automatically deployed to all Apollo-managed Foundry instances.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-49581",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-49581",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-02T20:46:08.213429Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@palantir.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@palantir.com",
      "affectedData": [
        {
          "vendor": "Palantir",
          "product": "com.palantir.gotham:external-artifacts",
          "versions": [
            {
              "status": "affected",
              "version": "*",
              "lessThan": "105.115.0",
              "versionType": "semver"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-12-02T21:15:10.830",
  "references": [
    {
      "url": "https://palantir.safebase.us/?tcuUid=b60db1ee-4b1a-475d-848e-c5a670a0da16",
      "source": "cve-coordination@palantir.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@palantir.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users.  \nThe affected service have been patched and automatically deployed to all Apollo-managed Foundry instances."
    },
    {
      "lang": "es",
      "value": "Restricted Views backed objects (OSV1) se puede omitir en circunstancias específicas debido a un error de software, lo que podría haber permitido que los usuarios que no tenían permiso para ver dichos objetos los vieran directamente a través del Explorador de objetos. Este error de software no afectó ni hizo que los datos estuvieran disponibles a través de los límites de la organización ni permitió que los usuarios no autenticados vieran o accedieran a los datos. El servicio afectado se ha parcheado y se ha implementado automáticamente en todas las instancias de Foundry administradas por Apollo."
    }
  ],
  "lastModified": "2026-06-17T08:00:00.607",
  "sourceIdentifier": "cve-coordination@palantir.com"
}