Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-52888

Опубликовано: 24 июн. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser (DocumentBuilderFactory) and allows external entity expansion when processing test result .xml files. This allows attackers to read arbitrary files from the file system and potentially trigger server-side request forgery (SSRF). Version 2.34.1 contains a patch for the issue.

EPSS

Процентиль: 10%
0.00036
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
github
8 месяцев назад

Allure Report allows Improper XXE Restriction via DocumentBuilderFactory

EPSS

Процентиль: 10%
0.00036
Низкий

7.5 High

CVSS3

Дефекты

CWE-611