QID 982050
QID 982050: Java (maven) Security Update for com.epam.reportportal:service-api (GHSA-24wf-7vf2-pv59)
Security update has been released for com.epam.reportportal:service-api to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Starting from version 3.1.0 we introduced a new feature of JUnit XML launch import. Unfortunately XML parser was not configured properly to prevent XML external entity (XXE) attacks. This allows a user to import a specifically-crafted XML file which imports external Document Type Definition (DTD) file with external entities for extraction of secrets from Report Portal service-api module or server-side request forgery.
Solution
Fixed with: https://github.com/reportportal/service-api/pull/1392
Vendor References
- GHSA-24wf-7vf2-pv59 -
github.com/advisories/GHSA-24wf-7vf2-pv59
CVEs related to QID 982050
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-24wf-7vf2-pv59 | com.epam.reportportal:service-api |
|