Vulnerability Description
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Talend | Data Catalog | < 8.0-20230413 |
Related Weaknesses (CWE)
References
- https://help.talend.com/r/en-US/Talend-Products-CVEs/Talend-Products-CVEsVendor Advisory
- https://help.talend.com/r/en-US/Talend-Products-CVEs/Talend-Products-CVEsVendor Advisory
FAQ
What is CVE-2023-33247?
CVE-2023-33247 is a vulnerability with a CVSS score of 7.5 (HIGH). Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote har...
How severe is CVE-2023-33247?
CVE-2023-33247 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-33247?
Check the references section above for vendor advisories and patch information. Affected products include: Talend Data Catalog.