Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x79h-5263-4x77

Опубликовано: 26 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)

EPSS

Процентиль: 31%
0.00121
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)

EPSS

Процентиль: 31%
0.00121
Низкий

7.5 High

CVSS3

Дефекты

CWE-306