
CVE-2023-31444
https://notcve.org/view.php?id=CVE-2023-31444
28 Apr 2023 — In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge. • https://talend.com • CWE-306: Missing Authentication for Critical Function •

CVE-2021-4311 – Talend Open Studio for MDM XML xml external entity reference
https://notcve.org/view.php?id=CVE-2021-4311
09 Jan 2023 — A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793. It is recommended to apply a patch to fix this issue. • https://github.com/Talend/tmdm-server-se/commit/31d442b9fb1d518128fd18f6e4d54e06c3d67793 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2022-4818 – Talend Open Studio for MDM SystemStorageWrapper.java xml external entity reference
https://notcve.org/view.php?id=CVE-2022-4818
28 Dec 2022 — A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java. The manipulation leads to xml external entity reference. Upgrading to version 20221220_1938 is able to address this issue. • https://github.com/Talend/tmdm-server-se/commit/95590db2ad6a582c371273ceab1a73ad6ed47853 • CWE-611: Improper Restriction of XML External Entity Reference •