本ページは talend data_catalog に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2023-36301 | Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet. | [email protected] | 7.5 | 0.93% | 2023-06-26 | 2026-06-17 |
| CVE-2023-33247 | Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.) | [email protected] | 7.5 | 0.46% | 2023-05-26 | 2026-06-17 |
| CVE-2023-26264 | All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code. | [email protected] | 5.5 | 0.21% | 2023-04-13 | 2026-06-17 |
| CVE-2023-26263 | All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server. | [email protected] | 5.5 | 0.22% | 2023-04-13 | 2026-06-17 |
| CVE-2021-42837 | An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username with an arbitrary password, and login will succeed. | [email protected] | 9.8 | 1.16% | 2021-11-05 | 2026-06-17 |