Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51007 | It was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify network communications to and from the affected service. In the case of a successful man in the middle attack on magritte-ftp, an attacker would be able to read and modify network traffic such as authentication tokens or raw data entering a Palantir Foundry stack. |
Tue, 18 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Palantir
Published:
Updated: 2025-03-18T15:05:06.264Z
Reserved: 2023-02-02T00:00:00.000Z
Link: CVE-2022-48307
Updated: 2024-08-03T15:10:59.695Z
Status : Modified
Published: 2023-02-16T16:15:12.333
Modified: 2024-11-21T07:33:07.950
Link: CVE-2022-48307
No data.
OpenCVE Enrichment
No data.
EUVD