{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2021-4311","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-01-09T11:19:07.872Z","datePublished":"2023-01-09T11:20:22.017Z","dateUpdated":"2025-04-09T19:25:57.677Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-10-20T13:46:51.508Z"},"title":"Talend Open Studio for MDM XML xml external entity reference","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-611","lang":"en","description":"CWE-611 XML External Entity Reference"}]}],"affected":[{"vendor":"Talend","product":"Open Studio for MDM","versions":[{"version":"n/a","status":"affected"}],"modules":["XML Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793. It is recommended to apply a patch to fix this issue. VDB-217666 is the identifier assigned to this vulnerability."},{"lang":"de","value":"In Talend Open Studio for MDM wurde eine Schwachstelle entdeckt. Sie wurde als problematisch eingestuft. Das betrifft eine unbekannte Funktionalität der Komponente XML Handler. Durch das Beeinflussen mit unbekannten Daten kann eine xml external entity reference-Schwachstelle ausgenutzt werden. Der Patch wird als 31d442b9fb1d518128fd18f6e4d54e06c3d67793 bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":5.5,"vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.5,"vectorString":"CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":4.9,"vectorString":"AV:A/AC:M/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2023-01-09T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2023-01-09T00:00:00.000Z","lang":"en","value":"CVE reserved"},{"time":"2023-01-09T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-01-30T11:31:31.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"VulDB GitHub Commit Analyzer","type":"tool"}],"references":[{"url":"https://vuldb.com/?id.217666","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.217666","tags":["signature","permissions-required"]},{"url":"https://github.com/Talend/tmdm-server-se/pull/1420","tags":["issue-tracking"]},{"url":"https://github.com/Talend/tmdm-server-se/commit/31d442b9fb1d518128fd18f6e4d54e06c3d67793","tags":["patch"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T17:23:10.354Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.217666","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.217666","tags":["signature","permissions-required","x_transferred"]},{"url":"https://github.com/Talend/tmdm-server-se/pull/1420","tags":["issue-tracking","x_transferred"]},{"url":"https://github.com/Talend/tmdm-server-se/commit/31d442b9fb1d518128fd18f6e4d54e06c3d67793","tags":["patch","x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-04-09T19:25:50.666132Z","id":"CVE-2021-4311","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-09T19:25:57.677Z"}}]}}