In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-04-28T00:00:00

Updated: 2024-08-02T14:53:30.958Z

Reserved: 2023-04-28T00:00:00

Link: CVE-2023-31444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-28T21:15:09.257

Modified: 2023-05-08T17:59:24.237

Link: CVE-2023-31444

cve-icon Redhat

No data.