help.talend.com
https://help.talend.com/r/en-US/7.3/release-notes-esb-products CVE-2021-40684
CRITICAL
Talend ESB Runtime Unauthenticated Jolokia HTTP Endpoint Vulnerability
Record summary
CVE-2021-40684 has a selected CVSS score of 9.1 (critical).
Description
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 25, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
esb_runtimeBrowse talend / esb_runtime | VulnCheck | Version data not supplied | |
References
3jira.talendforge.org
https://jira.talendforge.org/browse/SF-141 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-40684