CVE-2023-33247: Talend Data Catalog

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)

Affected products

  • Talend Data Catalog: before 8.0-20230413 (fixed in 8.0-20230413)

Published 2023-05-26. Last modified 2026-06-17.