Talend Administration Center privilege escalation | CVE-2022-29943
NAME
Talend Administration Center privilege escalation
- Platforms Affected:
Talend Talend Administration Center 8.0.0
Talend Talend Administration Center 7.3.0
Talend Talend Administration Center 7.2.0 - Risk Level:
8.8 - Exploitability:
Unproven - Consequences:
Gain Privileges
DESCRIPTION
Talend Administration Center could allow a remote authenticated attacker to gain elevated privileges on the system. By using XXE processing, an attacker could exploit this vulnerability to gain read access as root on the remote filesystem.
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Refer to the Talend Web site for patch, upgrade or suggested workaround information. See References.
- Reference Link:
https://www.talend.com/security/incident-response/ - Reference Link:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29943
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.