Softwareag Quartz vulnerabilities
2 known vulnerabilities affecting softwareag/quartz.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2023-39017CRITICALCVSS 9.8≤ 2.3.22023-07-28
CVE-2023-39017 [CRITICAL] CWE-94 CVE-2023-39017: quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the componen
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is not plausible that untrusted user input would reach the code location wh
nvd
CVE-2019-13990CRITICALCVSS 9.8fixed in 2.3.22019-07-26
CVE-2019-13990 [CRITICAL] CWE-611 CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
nvd