Data Catalog
Talend · 5 CVEs
CVE-2023-36301
HIGH
Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
Jun 26, 2023
CVE-2023-33247
HIGH
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenti…
May 26, 2023
CVE-2023-26264
MEDIUM
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks…
Apr 13, 2023
CVE-2023-26263
MEDIUM
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks…
Apr 13, 2023
CVE-2021-42837
CRITICAL
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not…
Nov 5, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-36301 | Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet. | HIGH | 0.93% | Jun 26, 2023 |
| CVE-2023-33247 | Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the ser… | HIGH | 0.46% | May 26, 2023 |
| CVE-2023-26264 | All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code. | MEDIUM | 0.21% | Apr 13, 2023 |
| CVE-2023-26263 | All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoin… | MEDIUM | 0.22% | Apr 13, 2023 |
| CVE-2021-42837 | An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login p… | CRITICAL | 1.20% | Nov 5, 2021 |
Showing 1 to 5 of 5 CVEs