Vulnerability Description
A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java. The manipulation leads to xml external entity reference. Upgrading to version 20221220_1938 is able to address this issue. The name of the patch is 95590db2ad6a582c371273ceab1a73ad6ed47853. It is recommended to upgrade the affected component. The identifier VDB-216997 was assigned to this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Talend | Open Studio For Mdm | < 20221220_1938 |
Related Weaknesses (CWE)
References
- https://github.com/Talend/tmdm-server-se/commit/95590db2ad6a582c371273ceab1a73adPatchThird Party Advisory
- https://github.com/Talend/tmdm-server-se/pull/1598Third Party Advisory
- https://github.com/Talend/tmdm-server-se/releases/tag/snap%2Fmaster%2F20221220_1Broken LinkThird Party Advisory
- https://vuldb.com/?ctiid.216997Third Party Advisory
- https://vuldb.com/?id.216997Third Party Advisory
- https://github.com/Talend/tmdm-server-se/commit/95590db2ad6a582c371273ceab1a73adPatchThird Party Advisory
- https://github.com/Talend/tmdm-server-se/pull/1598Third Party Advisory
- https://github.com/Talend/tmdm-server-se/releases/tag/snap%2Fmaster%2F20221220_1Broken LinkThird Party Advisory
- https://vuldb.com/?ctiid.216997Third Party Advisory
- https://vuldb.com/?id.216997Third Party Advisory
FAQ
What is CVE-2022-4818?
CVE-2022-4818 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/...
How severe is CVE-2022-4818?
CVE-2022-4818 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4818?
Check the references section above for vendor advisories and patch information. Affected products include: Talend Open Studio For Mdm.