StackRadar

CVE-2019-13990

Critical

Advisory

Published 1 Jul 2020In the index since 8 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.162
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

XML external entity injection in Terracotta Quartz Scheduler

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
quartzmaven1.8.7-atlassian-3, 2.1.7, 2.2.1, 2.2.3+2 more2.3.27
OSV records
GHSA-9qcf-c26r-x5rf

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2019-13990.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
quartz@2.3.1
2.3.2

Open the chart page →

9,144
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2019-13990.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
quartz@2.1.7
2.3.2

Open the chart page →

4,601
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2019-13990.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
quartz@2.3.0
2.3.2

Open the chart page →

23,665
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2019-13990.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
quartz@2.3.1
2.3.2

Open the chart page →

19,802
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2019-13990.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
quartz@2.2.3
2.3.2

Open the chart page →

63,223
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2019-13990.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
quartz@2.2.1
2.3.2

Open the chart page →

6,907
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2019-13990.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
quartz@1.8.7-atlassian-3
2.3.2

Open the chart page →

13,605

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
atlassian/confluence-server:7.10.03b9222ab32ef
quartz@1.8.7-atlassian-3
2.3.2
1
gocd/gocd-server:v19.3.02da45cb09d57
quartz@2.3.1
2.3.2
1
metabase/metabase:v0.31.2ffb2dccacefc
quartz@2.1.7
2.3.2
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
quartz@2.2.3
2.3.2
1
rundeck/rundeck:3.2.74d64fe56f767
quartz@2.3.1
2.3.2
1
rundeck/rundeck:3.0.16b13e8059ad72
quartz@2.3.0
2.3.2
1
xetusoss/archiva:v2.2.588f25242b9ee
quartz@2.2.1
2.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.