CVE-2022-27895

MEDIUM

Palantir Foundry Build2 < 1.785.0 - Log Information Exposure

Title source: rule
STIX 2.1

Description

Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions earlier than 1.785.0. Upgrade to Build2 version 1.785.0 or greater.

Scores

CVSS v3 4.2
EPSS 0.0021
EPSS Percentile 42.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (1)
palantir/foundry_build2 < 1.785.0
Published Nov 15, 2022
Tracked Since Feb 18, 2026