CVE-2020-12642
04.05.2020, 16:15
An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.Enginsight
Vendor | Product | Version |
---|---|---|
reportportal | service-api | 3.1.0 ≤ 𝑥 < 4.3.12 |
reportportal | service-api | 5.0.0 ≤ 𝑥 < 5.1.1 |
𝑥
= Vulnerable software versions