Vulnerability Description
In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Talend | Studio | < 7.3.1-r2022-10 |
Related Weaknesses (CWE)
References
- https://talend.comProduct
- https://www.talend.com/security/incident-response/#CVE-2023-31444Vendor Advisory
- https://talend.comProduct
- https://www.talend.com/security/incident-response/#CVE-2023-31444Vendor Advisory
FAQ
What is CVE-2023-31444?
CVE-2023-31444 is a vulnerability with a CVSS score of 7.5 (HIGH). In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM v...
How severe is CVE-2023-31444?
CVE-2023-31444 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31444?
Check the references section above for vendor advisories and patch information. Affected products include: Talend Studio.