First published: Mon May 04 2020(Updated: )
An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Reportportal Service-api | >=3.1.0<4.3.12 | |
Reportportal Service-api | >=5.0.0<5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12642 is considered a high severity vulnerability due to its potential for secrets disclosure and SSRF.
To remediate CVE-2020-12642, upgrade to Report Portal Service API version 4.3.12 or later, or 5.1.1 or later.
CVE-2020-12642 allows for XML External Entity (XXE) attacks, leading to sensitive information exposure and server-side request forgery (SSRF).
CVE-2020-12642 affects Report Portal Service API versions before 4.3.12 and 5.x before 5.1.1.
CVE-2020-12642 can be exploited for XXE attacks that may result in unauthorized data exposure and the capability to initiate requests to internal services.