Remote Code Execution Vulnerability in Talend Data Catalog
CVE-2023-33247
7.5HIGH
What is CVE-2023-33247?
The Talend Data Catalog prior to version 8.0-20230413 has a vulnerability in its remote harvesting server that exposes a /upgrade endpoint. This flaw allows an unauthenticated attacker to deploy a WAR file on the server, posing a significant security risk. To mitigate this issue, it is advised to ensure that the remote harvesting server is secured behind a firewall, which restricts access only to the Talend Data Catalog server.
