XML external entity injection in Terracotta Quartz Scheduler
Critical severity
GitHub Reviewed
Published
Jul 1, 2020
to the GitHub Advisory Database
•
Updated Oct 15, 2024
Description
Published by the National Vulnerability Database
Jul 26, 2019
Reviewed
Jul 1, 2020
Published to the GitHub Advisory Database
Jul 1, 2020
Last updated
Oct 15, 2024
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
References