CVE-2021-29620
Unfortunately the XML parser was not configured properly to prevent XML external entity (XXE) attacks.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML parsing was introduced. Unfortunately the XML parser was not configured properly to prevent XML external entity (XXE) attacks. This allows a user to import a specifically-crafted XML file which imports external Document Type Definition (DTD) file with external entities for extraction of secrets from Report Portal service-api module or server-side request forgery. This will be resolved in the 5.4.0 release.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- reportportal/service-api
- Source
- security-advisories@github.com
References
- https://github.com/reportportal/reportportal/security/advisories/GHSA-24wf-7vf2-pv59Patch, Third Party Advisory
- https://github.com/reportportal/service-api/pull/1392Patch, Third Party Advisory
- https://mvnrepository.com/artifact/com.epam.reportportal/service-apiRelease Notes, Third Party Advisory
- https://github.com/reportportal/reportportal/security/advisories/GHSA-24wf-7vf2-pv59Patch, Third Party Advisory
- https://github.com/reportportal/service-api/pull/1392Patch, Third Party Advisory
- https://mvnrepository.com/artifact/com.epam.reportportal/service-apiRelease Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.