CVE-2019-13990
XML external entity injection in Terracotta Quartz Scheduler
Description
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Base CVSS
9.8
EPSS Score
7.95%
Introduced Version
1.8.0
Fix Available
2.3.2
Available Patches
Package
CVEs Fixed
Lines of Code Changed