QID 980522
QID 980522: Java (maven) Security Update for com.epam.reportportal:service-api (GHSA-2jx8-v4hv-gx3h)
| Release Date | Affected Projects | Affected Versions | Access Vector| Security Risk |
|--------------|-------------------|-------------------|---------------|---------------|
| Monday, May 4, 2020| [service-api](https://github.com/reportportal/service-api) | Every version, starting from 3.1.0 | Remote | Medium |
Starting from version 3.1.0 we introduced a new feature of JUnit XML launch import. Unfortunately XML parser was not configured properly to prevent XML external entity (XXE) attacks. This allows a user to import a specifically-crafted XML file that uses external entities for extraction of secrets from Report Portal service-api module or server-side request forgery.
Report Portal versions 4.3.12+ and 5.1.1+ disables external entity resolution for theirs XML parser.
We advise our users install the latest releases we built specifically to address this issue.
- GHSA-2jx8-v4hv-gx3h -
github.com/advisories/GHSA-2jx8-v4hv-gx3h
CVEs related to QID 980522
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2jx8-v4hv-gx3h | com.epam.reportportal:service-api |
|