quartz is vulnerable to Remote Code Execution (RCE)
55
Medium Risk
Affected versions of the package are vulnerable to Remote Code Execution (RCE) when using the NativeJob class from the quartz-jobs artifact. Although it is possible to use this Job class securely, it poses a risk for users who do not take proper precautions, potentially allowing attackers to execute arbitrary code remotely.
You are affected if you are using a version which is within vulnerability ranges and if you are using the NativeJob class.
quartz is vulnerable to Remote Code Execution (RCE) in versions 2.1.4 - 2.3.2.
Upgrade the org.quartz-scheduler:quartz library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant