Skip to main content

Vendor archive

talend CVEs

Beta · best-effort

17 CVEs tagged to vendor talend3 Critical, 6 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2023-36301

Published Jun 26, 2023

Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33247

Published May 26, 2023

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31444

Published Apr 28, 2023

In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26264

Published Apr 13, 2023

All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26263

Published Apr 13, 2023

All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harv…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45589

Published Feb 6, 2023

All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the provisioning service only. Users o…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45588

Published Feb 3, 2023

All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30332

Published Jan 10, 2023

In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-4311

Published Jan 9, 2023

A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4818

Published Dec 28, 2022

A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31648

Published May 26, 2022

Talend Administration Center is vulnerable to a reflected Cross-Site Scripting (XSS) issue in the SSO login endpoint. The issue is fixed for versions 8.0.x in TPS-5233, for versio…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29943

Published May 4, 2022

Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesys…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29942

Published May 4, 2022

Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HTTP GET requests on URLs in the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42837

Published Nov 5, 2021

An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-40684

Published Sep 22, 2021

Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX o…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2228

Published Feb 19, 2020

The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2656

Published Dec 18, 2019

An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1