CVE-2023-22834: Palantir Contour
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.
Affected products
- Palantir Contour: before 9.642.0 (fixed in 9.642.0)
Published 2023-06-27. Last modified 2026-06-17.