Back

CRITICAL

libquartz: XXE attacks via job description

Published Jul 26, 2019

Description

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Affected products

Remediation

Red Hat statement

Red Hat Satellite 6 uses a vulnerable version of libquartz as a dependency for Candlepin. However, the <job><descrition> entry is not used, and the vulnerability can not be triggered. An update may fix the code in the future.

Metrics

Weaknesses (1)

References (33)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 26, 2019
Updated Oct 15, 2024
Reserved Jul 19, 2019
CISA Vulnrichment
Updated Oct 15, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 26, 2019
GHSA-9QCF-C26R-X5RF