Описание
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libquartz-java | fixed | 1:1.8.6-8 | package | |
| libquartz-java | no-dsa | bullseye | package | |
| libquartz-java | no-dsa | buster | package | |
| libquartz-java | no-dsa | stretch | package | |
| libquartz-java | no-dsa | jessie | package | |
| libquartz2-java | fixed | 2.3.0-3 | package | |
| libquartz2-java | no-dsa | buster | package | |
| libquartz2-java | no-dsa | stretch | package |
Примечания
https://github.com/quartz-scheduler/quartz/issues/467
https://github.com/quartz-scheduler/quartz/commit/a1395ba118df306c7fe67c24fb0c9a95a4473140
EPSS
Связанные уязвимости
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
XML external entity injection in Terracotta Quartz Scheduler
Уязвимость функции initDocumentParser библиотеки планирования заданий Terracotta Quartz Scheduler, позволяющая нарушителю осуществить XXE-атаку
EPSS