CVE-2021-40684
Last modified
CVE-2021-40684 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Talend | Esb Runtime | >= 5.1, < 7.1.1-r2021-09 |
References
- https://help.talend.com/r/en-US/7.3/release-notes-esb-productsRelease Notes, Vendor Advisory
- https://jira.talendforge.org/browse/SF-141Patch, Vendor Advisory
- https://help.talend.com/r/en-US/7.3/release-notes-esb-productsRelease Notes, Vendor Advisory
- https://jira.talendforge.org/browse/SF-141Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-40684?
How severe is CVE-2021-40684?
How do I fix CVE-2021-40684?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-40670SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via th…9.8
- CVE-2021-40674An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 vi…9.8
- CVE-2021-40678In Piwigo 11.5.0, there exists a persistent cross-site scrip…5.4
- CVE-2021-4068Insufficient data validation in new tab page in Google Chrom…6.5
- CVE-2021-40680There is a Directory Traversal vulnerability in Artica Proxy…8.1
- CVE-2021-40683In Akamai EAA (Enterprise Application Access) Client before …7.8
- CVE-2021-4069vim is vulnerable to Use After Free7.8
- CVE-2021-40690All versions of Apache Santuario - XML Security for Java pri…7.5
- CVE-2021-40691A session hijack risk was identified in the Shibboleth authe…4.3
- CVE-2021-40692Insufficient capability checks made it possible for teachers…4.3
- CVE-2021-40693An authentication bypass risk was identified in the external…6.5
- CVE-2021-40694Insufficient escaping of the LaTeX preamble made it possible…4.9
Are you affected by CVE-2021-40684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
