Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NTalend Data Catalog
APPTalend< 8.0-20230413
Related vulnerabilities
Talend Data Catalog — pominięcie uwierzytelniania na stronie logowania (Auth Bypass)
Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE...
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE...
Nieuwierzytelniony dostęp do endpointu Jolokia JMX w Talend ESB Runtime