Bug 2247104 (CVE-2023-39017) - CVE-2023-39017 quartz-jobs: potential code injection vulnerability
Summary: CVE-2023-39017 quartz-jobs: potential code injection vulnerability
Status: NEW
Alias: CVE-2023-39017
Reported: 2023-10-30 17:23 UTC
Modified: 2024-01-24 12:50 UTC
A code injection vulnerability was found in quartz-jobs. The issue resides in the org.quartz.jobs.ee.jms.SendQueueMessageJob.execute component, where an unchecked argument can trigger the vulnerability.
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is not plausible that untrusted user input would reach the code location where injection must occur.


