Описание
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
The Terracotta Quartz Scheduler is susceptible to an XML external entity attack (XXE) through a job description. This issue stems from inadequate handling of XML external entity (XXE) declarations in the initDocumentParser function within xml/XMLSchedulingDataProcessor.java. By enticing a victim to access a maliciously crafted job description (containing XML content), a remote attacker could exploit this vulnerability to execute an XXE attack on the targeted system.
Отчет
Red Hat Satellite 6 uses a vulnerable version of libquartz as a dependency for Candlepin. However, the entry is not used, and the vulnerability can not be triggered. An update may fix the code in the future.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Fuse Service Works 6 | quartz | Out of support scope | ||
| Red Hat Satellite 5 | quartz | Out of support scope | ||
| Red Hat Satellite 6 | quartz | Fix deferred | ||
| Red Hat Decision Manager 7 | quartz | Fixed | RHSA-2020:3196 | 29.07.2020 |
| Red Hat Fuse 7.8.0 | quartz | Fixed | RHSA-2020:5568 | 16.12.2020 |
| Red Hat Process Automation 7 | quartz | Fixed | RHSA-2020:3197 | 29.07.2020 |
| Red Hat Virtualization Engine 4.4 | rhvm-dependencies | Fixed | RHSA-2020:3247 | 04.08.2020 |
Показывать по
Дополнительная информация
Статус:
8.1 High
CVSS3
Связанные уязвимости
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracott ...
XML external entity injection in Terracotta Quartz Scheduler
Уязвимость функции initDocumentParser библиотеки планирования заданий Terracotta Quartz Scheduler, позволяющая нарушителю осуществить XXE-атаку
8.1 High
CVSS3