Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-39017


quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is not plausible that untrusted user input would reach the code location where injection must occur.


Published

2023-07-28T15:15:13.160

Last Modified

2024-11-21T08:14:37.730

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application softwareag quartz ≤ 2.3.2 Yes

References