Skip to main content

Vendor/product archive

talend / data_catalog CVEs

Beta · best-effort

5 CVEs tagged to talend / data_catalog1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-36301

Published Jun 26, 2023

Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33247

Published May 26, 2023

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26264

Published Apr 13, 2023

All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26263

Published Apr 13, 2023

All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harv…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42837

Published Nov 5, 2021

An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1