Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2021-40684
Disclosure Date: September 22, 2021 (last updated November 28, 2024)
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.
1
Attacker Value
Unknown
CVE-2023-36301
Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
0
Attacker Value
Unknown
CVE-2023-33247
Disclosure Date: May 26, 2023 (last updated October 08, 2023)
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)
0
Attacker Value
Unknown
CVE-2023-31444
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.
0
Attacker Value
Unknown
CVE-2023-26264
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.
0
Attacker Value
Unknown
CVE-2023-26263
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.
0
Attacker Value
Unknown
CVE-2022-45589
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the provisioning service only. Users of the provisioning service should upgrade to either 8.0.1-R2022-10-RT or 7.3.1-R2022-09-RT or a later release and use it in place of the previous version.
0
Attacker Value
Unknown
CVE-2022-45588
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or later and use it in place of the previous version. Talend Remote Engine Gen 1 and Talend Cloud Engine for Design are not impacted. This XXE vulnerability could only be exploited by someone with the appropriate rights to edit pipelines on the Talend platform. It could not be triggered remotely or by other user input.
0
Attacker Value
Unknown
CVE-2022-30332
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests.
0
Attacker Value
Unknown
CVE-2021-4311
Disclosure Date: January 09, 2023 (last updated October 20, 2023)
A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793. It is recommended to apply a patch to fix this issue. VDB-217666 is the identifier assigned to this vulnerability.
0