Security incident response information


Publication Date: May 3, 2022

CVE-2022-29942 and CVE-2022-29943


Publication Date: April 5, 2022

Spring4Shell (CVE 2022-22965; CVE-2022-22963)

Talend is aware of and monitoring CVE 2022-22965 and CVE-2022-22963 security vulnerabilities for whether they affect any of our Talend products.

We have been working diligently on addressing the situation throughout our Product portfolio and are in process of developing the code fix to address the impacted Products.

For updates on our investigation and what you can do to assist remediation or mitigation of the vulnerability, please periodically visit the documentation page located at https://help.talend.com/r/RUfDtlfQvuDzJUZC4P9Z9g/7G3ZMXPTMt2klpS~SJ0vtg

As of April 1, 2022, we implemented blocking of external exploitation attempts on Talend Cloud Products for these CVEs.


Publication Date: February 10, 2022

CVE-2021-40684 and CVE-2021-42837


Publication Date: January 18, 2022

Log4j2 Issue (CVE-2021-44228)

CVE-2021-44228 and CVE-2021-45046

Talend is aware of the recently disclosed vulnerabilities related to the open-source Apache Software Foundation “Log4j2" utility (reported under CVE-2021-44228 and CVE-2021-45046 as critical severity level). Talend has patched all relevant Products to remedy these vulnerabilities.

Here, you can find additional Product specific information regarding remediation efforts. Certain Talend Products may require configuration changes, which will be shared as they become available. Until deployment of Log4j v2.16, please follow the steps below.

CVE-2021-45105 and CVE-2021-44832

Talend is aware of the recently disclosed medium severity vulnerabilities reported under CVE-2021-45105 and CVE-2021-44832 related to the open-source Apache Software Foundation “Log4j2" utility.

CVE-2021-45105 is only applicable when the logging configuration uses a non-default Pattern Layout with a Context Lookup. By default, Talend Products do not use Context Lookups, meaning the vulnerability is only applicable if the Customer manually changed the logging configuration. For Customers that manually changed the logging configuration, the CVE-2021-45105 vulnerability is addressed in Log4J 2.17.0. For Remote Engine Gen1, CVE-2021-45105, Talend addressed the CVE-2021-45105 vulnerability by updating to Log4J 2.17.0 in version 2.11.7.

CVE-2021-44832 is only applicable when the logging configuration uses a JDBC appender with a JNDI data source, or the log4j configuration is modified by an attacker. Talend products do not use a JDBC appended by default for logging. The CVE-2021-44832 vulnerability is addressed in Log4J 2.17.1.

Both medium severities CVEs are resolved with Log4j 2.17.1., which will be released during Talend’s monthly patch within its Continuous Maintenance Development process.

If you need additional details or assistance, please contact Talend Support on Talend Support portal (https://login.talend.com/support-login.php) or by sending an e-mail to customercare@talend.com.


References

Apache Log4j2 CVE-2021-44228 
Apache Log4j2 CVE-2021-45046
Apache Log4j Security Vulnerabilities


Changelog

2022.01.18
- TDC On-Prem section update

2022.01.07
-  EOL versions evaluation sentence updated

2022.01.06
- “References” Section updated

2022.01.04
- “Summary” Table updated:

  • ESB Runtime 7.1.1 Patch information updated
  • Remote Engine Gen1 (Marketplace) patch information updated
  • Talend Cloud Application updated

2021.12.28
- “Summary” Table updated:

  • ESB Runtime 7.3.1 Patch information updated
  • LogServer 7.1.1 Patch information updated

2021.12.27
- “Summary” Table updated:

  • Talend Studio 7.2.1 and 7.1.1 Patch information updated
  • IAM 7.1.1 Patch information updated

2021.12.24
- “Summary” Table updated:

  • ESB Runtime 7.2.1 Patch information updated
  • Remote Engine Gen1 Patch information updated
  • Remote Engine Gen1 (Marketplace) Patch information updated
  • Talend Data Catalog Patch information updated

2021.12.23
- “Summary” Table updated:

  • ESB Runtime 7.3.1 Patch information updated: Pending Date
  • ESB Runtime 8.0.1 Patch information updated
  • Remote Engine Gen 1 Patch information updated: Pending Date
  • Talend Data Catalog Patch information updated: Pending Date

2021.12.22
- “Summary” Table updated:

  • Studio 7.3.1 Patch information updated

2021.12.21
- “Summary” Table updated with:

  • available patch information
  • Studio Mitigation information update

2021.12.20
- “Summary” Table updated:

  • ESB Runtime 7.1.1 Mitigation and Patch information added
  • IAM 7.1.1 Mitigation and Patch information added
  • LogServer 7.1.1 Mitigation and Patch information added
  • JobServer 7.1.1 Mitigation and Patch information added
  • MDM 7.1.1 Mitigation and Patch information added
  • Talend Administration Center (TAC) Mitigation and Patch information added
  • Talend Data Preparation 7.1.1 Mitigation and Patch information added
  • Talend Data Stewardship 7.1.1 Mitigation and Patch information added
  • Talend Studio On-prem 7.1.1 Mitigation and Patch information added

- Section “Mitigation steps for TAC” updated
- Section “Mitigation steps for ESB Runtime” updated with pre-requisite instructions for 7.2.1 and 7.1.1
- Section “Mitigation steps for Remote Engine Gen1” updated with optional step if “impersonate job” feature used

2021.12.17
- “Summary” Table updated:

  • Talend Data Preparation Mitigation and Patch information added
  • Talend Data Stewardship Mitigation and Patch information added
  • Talend Remote Engine Gen1 (Marketplace) Mitigation and Patch information added
  • Talend Studio Cloud Mitigation information updated
  • Talend Studio on-prem Mitigation and Patch 7.2 information updated

- Section “Mitigation steps for IAM” - startup script updated
- Section “Mitigation steps for MDM” - startup script updated
- Section “Mitigation steps for TAC” - startup script updated

2021.12.16
- “Summary” Table updated:

  • ESB Runtime patch information updated
  • Jobserver Mitigation and Patch information updated
  • MDM Mitigation updated
  • Remote Engine Gen1 Patch information updated
  • Talend Data Catalog Mitigation and Patch updated
  • Talend Studio Mitigation and Patch information updated

- Section “Mitigaton steps for ESB Runtime” updated with new parameter JAVA_TOOL_OPTIONS
- Section “Mitigaton steps for JobServer” updated with specific instructions per version
- Section “Mitigation steps for MDM” added
- Section “Mitigation steps for Remote Engine Gen1” updated with new parameter JAVA_TOOL_OPTIONS

2021.12.15
- Original version

Summary

Remediation for Talend Open Source is not in scope. End-of-Life versions evaluations have been completed. For further details, please contact Talend Support.

Additional Details