PT-2023-14712 · Talend · Talend Esb Runtime+1
Published
2023-02-03
·
Updated
2025-03-26
·
CVE-2022-45588
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Talend Remote Engine Gen 2 versions prior to R2022-09
Talend ESB Runtime versions prior to 7.3.1-R2022-09-RT
Talend ESB Runtime versions prior to 8.0.1-R2022-10-RT
Description
The issue is related to XML External Entity (XXE) and SQL Injection attacks. For the XXE vulnerability, it could only be exploited by someone with the appropriate rights to edit pipelines on the Talend platform and could not be triggered remotely or by other user input. The SQL Injection attacks are limited to the provisioning service.
Recommendations
For Talend Remote Engine Gen 2 versions prior to R2022-09, download the R2022-09 release or later and use it in place of the previous version.
For Talend ESB Runtime versions prior to 7.3.1-R2022-09-RT, upgrade to 7.3.1-R2022-09-RT or a later release.
For Talend ESB Runtime versions prior to 8.0.1-R2022-10-RT, upgrade to 8.0.1-R2022-10-RT or a later release.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Talend Esb Runtime
Talend Remote Engine Gen 2