CVE-2023-39017 describes a critical code injection vulnerability (CWE-94) in quartz-jobs versions 2.3.2 and below, specifically within the org.quartz.jobs.ee.jms.SendQueueMessageJob.execute component, affecting Software AG Quartz products. This flaw, rated 9.8 CVSS (CRITICAL), allows for remote, low-complexity attacks with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While the vulnerability is severe, its exploitability is disputed due to the unlikelihood of untrusted input reaching the vulnerable code. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.2CPE matchmatch criteria | cpe:2.3:a:softwareag:quartz:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.