CVE-2020-12642

An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:reportportal:service-api:*:*:*:*:*:*:*:*
cpe:2.3:a:reportportal:service-api:*:*:*:*:*:*:*:*

Information

Published : 2020-05-04 09:15

Updated : 2020-05-07 09:48


NVD link : CVE-2020-12642

Mitre link : CVE-2020-12642


JSON object : View

CWE
CWE-611

Improper Restriction of XML External Entity Reference

Advertisement

dedicated server usa

Products Affected

reportportal

  • service-api