ReportPortal is a test-reporting and quality-management platform whose vulnerability profile centers on its service API components and reflects resource-handling and XML-processing exposures. The recurring weakness classes—XML external entity injection and unbounded resource allocation—point to input-validation and capacity-management gaps characteristic of web-service architectures. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reportportal over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29620HIGH Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML parsing was introduced. Unfortunately the XML parser was not co | Jun 23, 2021 | 7.5 | 23 | NO | NO |
CVE-2023-25822MEDIUM ReportPortal is an AI-powered test automation platform. Prior to version 5.10.0 of the `com.epam.reportportal:service-api` module, corresponding to ReportPortal version 23.2, the R | Oct 9, 2023 | 6.5 | 20 | NO | NO |
CVE-2020-12642HIGH An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import. | May 4, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reportportal.
Media articles that mention a CVE ID that affects a product developed by Reportportal — matched by CVE ID, not by vendor name.