Remote Code Execution Vulnerability in Talend Data Catalog
CVE-2023-33247

7.5HIGH

Key Information:

Vendor

Talend

Vendor
CVE Published:
26 May 2023

What is CVE-2023-33247?

The Talend Data Catalog prior to version 8.0-20230413 has a vulnerability in its remote harvesting server that exposes a /upgrade endpoint. This flaw allows an unauthenticated attacker to deploy a WAR file on the server, posing a significant security risk. To mitigate this issue, it is advised to ensure that the remote harvesting server is secured behind a firewall, which restricts access only to the Talend Data Catalog server.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.