Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39017

Опубликовано: 19 июл. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is not plausible that untrusted user input would reach the code location where injection must occur.

A code injection vulnerability was found in quartz-jobs. The issue resides in the org.quartz.jobs.ee.jms.SendQueueMessageJob.execute component, where an unchecked argument can trigger the vulnerability.

Отчет

This issue only affects the quartz-jobs artifact, and we are not using it in Quarkus, so we are not affected. NOTE: Multiple parties challenge this assertion, arguing that it is implausible for untrusted user input to reach the specific code location where injection must take place.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7quartzNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2247104quartz-jobs: potential code injection vulnerability

EPSS

Процентиль: 71%
0.00696
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is not plausible that untrusted user input would reach the code location where injection must occur.

CVSS3: 9.8
nvd
больше 2 лет назад

quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is not plausible that untrusted user input would reach the code location where injection must occur.

CVSS3: 9.8
debian
больше 2 лет назад

quartz-jobs 2.3.2 and below was discovered to contain a code injection ...

CVSS3: 9.8
github
больше 2 лет назад

quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument.

EPSS

Процентиль: 71%
0.00696
Низкий

5.3 Medium

CVSS3