Critical severity9.1NVD Advisory· Published Sep 22, 2021· Updated Jun 17, 2026
CVE-2021-40684
CVE-2021-40684
Description
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.
Affected products
3cpe:2.3:a:talend:esb_runtime:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:talend:esb_runtime:*:*:*:*:*:*:*:*range: >=5.1,<7.1.1-r2021-09
- (no CPE)
Patches
Vulnerability mechanics
References
2- jira.talendforge.org/browse/SF-141nvdPatchVendor Advisory
- help.talend.com/r/en-US/7.3/release-notes-esb-productsnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.