Notable fixes and Known issues in Talend Remote Engine R2023-06 - Cloud - 8.0

Talend Release Notes

Version
Cloud
8.0
Language
English
Product
Talend Big Data
Talend Big Data Platform
Talend Cloud API Services Platform
Talend Cloud Big Data
Talend Cloud Big Data Platform
Talend Cloud Data Fabric
Talend Cloud Data Integration
Talend Cloud Data Management Platform
Talend Data Fabric
Talend Data Integration
Talend Data Management Platform
Talend Data Services Platform
Talend ESB
Talend MDM Platform
Talend Real-Time Big Data Platform
Module
Talend Cloud API Designer
Talend Cloud API Tester
Talend Cloud Data Inventory
Talend Cloud Data Preparation
Talend Cloud Data Stewardship
Talend Cloud Management Console
Talend Cloud Pipeline Designer
Talend Data Preparation
Talend Data Stewardship
Talend Studio
Content
Installation and Upgrade
Release Notes
Last publication date
2023-12-01

Security enhancements

Issue Description
TPOPS-6127 A Spring Vault Core medium severity vulnerability has been repaired:
  • CVE-2023-20859
TPOPS-6130
Jettison has been upgraded to repair a high severity vulnerability:
  • CVE-2023-1436
TPOPS-6131 Spring Expression Language (SpEL) is using v5.3.27 to avoid several medium severity vulnerabilities:
  • CVE-2023-20861 - Denial Of Service (DoS)
  • CVE-2023-20863 - Denial Of Service (DoS)
TPOPS-6255 Jose4j is using a new version to avoid its "Improper Cryptographic Algorithm" issue.
TPOPS-6297 Jetty's new version helps repair several medium severity vulnerabilities:
  • CVE-2023-26048: OutOfMemoryError occurs for large multipart file without filename in Eclipse Jetty.
  • CVE-2023-26049: Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies.
TPOPS-6353 Sensitive data is not visible anymore in the karaf.log file of Remote Engine.

Available in:

Cloud API Services Platform

Cloud Data Fabric

TPRUN-3701
The default credentials for a data server runner has been removed. For further information about the new approach to define your JMX credentials, see Customizing global OSGi configuration.

Notable fixes

Issue Description
TPOPS-6275 Special characters and characters from languages such as Chinese or Japanese are garbled in the task run logs.
TPOPS-6222 The org.talend.observability.client.tcp.TcpClient file in the send() method is blocking the termination of task runs.
TINSTL-2634 Installation of Remote Engine 2.12.11 fails with the following exception:
No more authentication methods available

Available in:

Cloud API Services Platform

Cloud Data Fabric

APPINT-35108

Unexpected yellow exclamation marks appear beside the Running status when microservice Routes are being deployed to Remote Engine.