#VU19595 XML External Entity injection in Quartz Scheduler - CVE-2019-13990
Published: August 1, 2019 / Updated: November 19, 2019
Quartz Scheduler
Terracotta
Description
The vulnerability allows a remote attacker to conduct an XML External Entity (XXE) attack on a targeted system.
The vulnerability exists due to insufficient validation of user-supplied XML input in the "initDocumentParser" function in the "xml/XMLSchedulingDataProcessor.java" file. A remote authenticated attacker can submit a malicious job description to the targeted system and conduct an XXE attack.