In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0...
High severity
Unreviewed
Published
Apr 28, 2023
to the GitHub Advisory Database
•
Updated Jan 31, 2025
Description
Published by the National Vulnerability Database
Apr 28, 2023
Published to the GitHub Advisory Database
Apr 28, 2023
Last updated
Jan 31, 2025
In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.
References