Lucene search

K
osvGoogleOSV:GHSA-9QCF-C26R-X5RF
HistoryJul 01, 2020 - 5:55 p.m.

XML external entity injection in Terracotta Quartz Scheduler

2020-07-0117:55:03
Google
osv.dev
41

0.008 Low

EPSS

Percentile

81.1%

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

References