Lucene search

K

Talend Security Vulnerabilities

cve
cve

CVE-2022-30332

In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of...

5.3CVSS

5.3AI Score

0.002EPSS

2023-01-10 09:15 PM
15
cve
cve

CVE-2021-4311

A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793. It is recommended...

9.8CVSS

9.5AI Score

0.002EPSS

2023-01-09 12:15 PM
23
cve
cve

CVE-2022-4818

A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java. The manipulation leads to xml external entity reference....

5.5CVSS

4.8AI Score

0.001EPSS

2022-12-28 09:15 PM
29
cve
cve

CVE-2023-36301

Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in...

7.5CVSS

7.5AI Score

0.001EPSS

2023-06-26 03:15 PM
11
cve
cve

CVE-2023-33247

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog...

7.5CVSS

7.5AI Score

0.001EPSS

2023-05-26 08:15 PM
15
cve
cve

CVE-2023-31444

In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP...

7.5CVSS

7.6AI Score

0.002EPSS

2023-04-28 09:15 PM
13
cve
cve

CVE-2023-26263

All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting...

5.5CVSS

5.5AI Score

0.001EPSS

2023-04-13 07:15 PM
13
cve
cve

CVE-2023-26264

All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing...

5.5CVSS

5.5AI Score

0.001EPSS

2023-04-13 07:15 PM
123
2
cve
cve

CVE-2022-45589

All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the provisioning service only. Users of the provisioning service should upgrade to either 8.0.1-R2022-10-RT or 7.3.1-R2022-09-RT or a later release and use...

7.2CVSS

7.3AI Score

0.001EPSS

2023-02-06 09:15 PM
22
cve
cve

CVE-2022-45588

All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or later and use it in place of the previous version. Talend Remote Engine Gen 1 and Talend Cloud Engine for Design are...

7.8CVSS

7.6AI Score

0.0004EPSS

2023-02-03 09:15 PM
22
cve
cve

CVE-2022-31648

Talend Administration Center is vulnerable to a reflected Cross-Site Scripting (XSS) issue in the SSO login endpoint. The issue is fixed for versions 8.0.x in TPS-5233, for versions 7.3.x in TPS-5324, and for versions 7.2.x in TPS-5235. Earlier versions of Talend Administration Center may also be.....

6.1CVSS

5.8AI Score

0.001EPSS

2022-05-26 08:15 PM
34
4
cve
cve

CVE-2022-29942

Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HTTP GET requests on URLs in the internal network. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175, and versions 7.2.x in....

6.5CVSS

6.2AI Score

0.001EPSS

2022-05-04 06:15 PM
45
cve
cve

CVE-2022-29943

Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesystem. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175, and versions 7.2.x in TPS-5201....

6.5CVSS

6.1AI Score

0.001EPSS

2022-05-04 06:15 PM
57
cve
cve

CVE-2021-42837

An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username with an arbitrary password, and login will...

9.8CVSS

9.5AI Score

0.003EPSS

2021-11-05 06:15 PM
20
cve
cve

CVE-2021-40684

Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running.....

9.1CVSS

9AI Score

0.002EPSS

2021-09-22 05:15 PM
29
cve
cve

CVE-2014-2228

The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML...

9.8CVSS

9.7AI Score

0.013EPSS

2020-02-19 02:15 PM
21
cve
cve

CVE-2012-2656

An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive...

7.5CVSS

7.5AI Score

0.002EPSS

2019-12-18 07:15 PM
19