{"id":"GHSA-24wf-7vf2-pv59","summary":"XXE vulnerability on Launch import with externally-defined DTD file","details":"### Impact\nStarting from version 3.1.0 we introduced a new feature of JUnit XML launch import. Unfortunately XML parser was not configured properly to prevent XML external entity (XXE) attacks. This allows a user to import a specifically-crafted XML file which imports external Document Type Definition (DTD) file with external entities for extraction of secrets from Report Portal service-api module or server-side request forgery.\n\n### Patches\nFixed with: https://github.com/reportportal/service-api/pull/1392\n\n### Binaries\n`docker pull reportportal/service-api:5.4.0`\nhttps://github.com/reportportal/service-api/packages/846871?version=5.4.0\n\n### For more information\nIf you have any questions or comments about this advisory email us: [support@reportportal.io](mailto:support@reportportal.io)\n","aliases":["CVE-2021-29620"],"modified":"2026-07-08T06:30:02.971100291Z","published":"2021-06-28T16:38:29Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-06-25T13:06:33Z","nvd_published_at":"2021-06-23T18:15:00Z","cwe_ids":["CWE-611"]},"references":[{"type":"WEB","url":"https://github.com/reportportal/reportportal/security/advisories/GHSA-24wf-7vf2-pv59"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29620"},{"type":"WEB","url":"https://github.com/reportportal/service-api/pull/1392"},{"type":"WEB","url":"https://github.com/reportportal/service-api/commit/a73e0dfb4eda844c37139df1f9847013d55f084e"},{"type":"WEB","url":"https://mvnrepository.com/artifact/com.epam.reportportal/service-api"}],"affected":[{"package":{"name":"com.epam.reportportal:service-api","ecosystem":"Maven","purl":"pkg:maven/com.epam.reportportal/service-api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.0"},{"fixed":"5.4.0"}]}],"versions":["3.1.1","3.2.0","3.2.1","3.3.2","4.0.0","4.1.1","4.2.1","4.3.10","4.3.11","4.3.12","5.0.0","5.1.0","5.1.1","5.2.0","5.2.1","5.2.2","5.2.3","5.3.0","5.3.1","5.3.2","5.3.3","5.3.4","5.3.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-24wf-7vf2-pv59/GHSA-24wf-7vf2-pv59.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}