{"id":"CVE-2020-12642","aliases":["GHSA-2jx8-v4hv-gx3h"],"url":"https://o3.security/vulnerability/CVE-2020-12642","summary":"XXE vulnerability in Launch import","details":"| Release Date | Affected Projects | Affected Versions | Access Vector| Security Risk |\n|--------------|-------------------|-------------------|---------------|---------------|\n| Monday, May 4, 2020| [service-api](https://github.com/reportportal/service-api) | Every version, starting from 3.1.0 | Remote | Medium |\n\n### Impact\nStarting from version 3.1.0 we introduced a new feature of JUnit XML launch import. Unfortunately XML parser was not configured properly to prevent XML external entity (XXE) attacks. This allows a user to import a specifically-crafted XML file that uses external entities for extraction of secrets from Report Portal service-api module or server-side request forgery.\n\nReport Portal versions 4.3.12+ and 5.1.1+ disables external entity resolution for theirs XML parser.\n\nWe advise our users install the latest releases we built specifically to address this issue.\n\n### Patches\nFixed with https://github.com/reportportal/service-api/pull/1201\n\n### Binary Download\nhttps://bintray.com/epam/reportportal/service-api/5.1.1\nhttps://bintray.com/epam/reportportal/service-api/4.3.12\n\n### Docker Container Download\n* RP v4: `docker pull reportportal/service-api:4.3.12`\n* RP v5: `docker pull reportportal/service-api:5.1.1`\n\n### Acknowledgement\nThe issue was reported to Report Portal Team by an external security researcher.\nOur Team thanks Julien M. for reporting the issue.\n\n### For more information\nIf you have any questions or comments about this advisory email us: [support@reportportal.io](mailto:support@reportportal.io)","published":"2020-05-04T16:15:12.147Z","modified":"2026-07-08T17:56:38.570877Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.01349,"percentile":0.70064,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.epam.reportportal:service-api","fixedVersion":"4.3.12"},{"ecosystem":"Maven","name":"com.epam.reportportal:service-api","fixedVersion":"5.1.1"}],"fix":{"url":"https://github.com/reportportal/service-api/pull/1201","label":"reportportal/service-api#1201"},"references":[{"type":"FIX","url":"https://github.com/reportportal/reportportal/blob/master/SECURITY_ADVISORIES.md"},{"type":"WEB","url":"https://github.com/reportportal/reportportal/security/advisories/GHSA-2jx8-v4hv-gx3h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-12642"},{"type":"WEB","url":"https://github.com/reportportal/service-api/pull/1201"},{"type":"WEB","url":"https://github.com/reportportal/service-api/commit/da4a012abdcc69f02f4255d81466f1f473b7f418"},{"type":"PACKAGE","url":"https://github.com/reportportal/reportportal"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T17:56:38.570877Z"}}