Lucene search

K
redhatcveRedhat.comRH:CVE-2019-13990
HistoryFeb 10, 2020 - 11:44 a.m.

CVE-2019-13990

2020-02-1011:44:18
redhat.com
access.redhat.com
41

9.3 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.1%

The Terracotta Quartz Scheduler is susceptible to an XML external entity attack (XXE) through a job description. This issue stems from inadequate handling of XML external entity (XXE) declarations in the initDocumentParser function within xml/XMLSchedulingDataProcessor.java. By enticing a victim to access a maliciously crafted job description (containing XML content), a remote attacker could exploit this vulnerability to execute an XXE attack on the targeted system.