Aller au contenu

Fiche vulnérabilité

CVE-2021-40684 : faille critique talend esb runtime (CVSS 9.1)

Description

Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
22 sept. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • talend esb runtime

Références

Rechercher une autre vulnérabilité dans la base CVE