initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description (CVE-2019-13990).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2021-0133.json"