XML External Entity Vulnerability in Talend Data Catalog by Talend
CVE-2023-26263

5.5MEDIUM

Key Information:

Vendor

Talend

Vendor
CVE Published:
13 April 2023

What is CVE-2023-26263?

Talend Data Catalog versions prior to 8.0-20230110 are susceptible to XML External Entity (XXE) attacks through the /MIMBWebServices/license endpoint. This vulnerability could allow an attacker to access sensitive data or perform unauthorized actions, thereby compromising the integrity and confidentiality of the application. It is essential to update to the latest version to mitigate this risk.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.