initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. 

Issue date: 15-01-2020
Affects versions: 13.4, 13.3, 12.5, 11.2

Issue ID

SECURITY-143

 

Affected Product Version(s)

13.4.0, 12.6.7, 11.2.16 (and previous patch releases)


Severity 

Medium

Description

Terracotta Quartz Scheduler reported vulnerability CVE-2019-13990 in versions through 2.3.0.

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Terracotta Quartz has been updated to 2.3.2.

Instructions

Every customer is advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.