CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. Exploitation may require the attacker to be authenticated.
CVE
CVE-2022-29942
Severity
MEDIUM
CVSS
6.5
EPSS
0.66%
Original NVD Description
Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HTTP GET requests on URLs in the internal network. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175, and versions 7.2.x in TPS-5201. Earlier versions of Talend Administration Center may also be impacted; users are encouraged to update to a supported version.
Related CVEs
Other vulnerabilities affecting the same vendor(s)