XML injection (XXE) In com.epam.reportportal:service-api
Description
XML External Entity Reference An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 4.3.12, 5.1.1 |
Aliases
1. 2.
References
1.