High severityNVD Advisory· Published May 4, 2020· Updated Aug 4, 2024
CVE-2020-12642
CVE-2020-12642
Description
An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.epam.reportportal:service-apiMaven | >= 3.1.0, < 4.3.12 | 4.3.12 |
com.epam.reportportal:service-apiMaven | >= 5.0.0, < 5.1.1 | 5.1.1 |
Affected products
2- Report Portal/Report Portaldescription
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-2jx8-v4hv-gx3hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-12642ghsaADVISORY
- github.com/reportportal/reportportal/blob/master/SECURITY_ADVISORIES.mdmitrex_refsource_CONFIRM
- github.com/reportportal/reportportal/security/advisories/GHSA-2jx8-v4hv-gx3hghsaWEB
- github.com/reportportal/service-api/commit/da4a012abdcc69f02f4255d81466f1f473b7f418ghsaWEB
- github.com/reportportal/service-api/pull/1201ghsaWEB
News mentions
0No linked articles in our index yet.