CVE-2024-49581 - CVE House
Back to Database
Status published Medium CVE-2024-49581

Access control issue impacting RV backed objects

Vulnerability Description

Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users. The affected service have been patched and automatically deployed to all Apollo-managed Foundry instances.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-49581

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

com.palantir.gotham:external-artifacts
Vulnerable Versions:
*

Timeline

Official Publish: December 2nd, 2024
Last Modified: December 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)