Security Advisory

CVE-2024-49587

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-19 16:33:22
Last updated 2026-02-26 16:07:24
Assigner Palantir
State PUBLISHED

Description

Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directly and read/update/delete data. The affected service has been patched and automatically deployed to all Apollo-managed Gotham Instances