Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.qameta.allure.plugins/junit-xml-plugin
  4. ›
  5. CVE-2025-52888

CVE-2025-52888: Allure Report allows Improper XXE Restriction via DocumentBuilderFactory

June 25, 2025

A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2. The plugin fails to securely configure the XML parser (DocumentBuilderFactory) and allows external entity expansion when processing test result .xml files. This allows attackers to read arbitrary files from the file system and potentially trigger server-side request forgery (SSRF).

References

  • github.com/advisories/GHSA-h7qf-qmf3-85qg
  • github.com/allure-framework/allure2
  • github.com/allure-framework/allure2/commit/cbcb33719851ff70adce85d38e15d20fc58d4eb7
  • github.com/allure-framework/allure2/security/advisories/GHSA-h7qf-qmf3-85qg
  • nvd.nist.gov/vuln/detail/CVE-2025-52888

Code Behaviors & Features

Detect and mitigate CVE-2025-52888 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.34.1

Fixed versions

  • 2.34.1

Solution

Upgrade to version 2.34.1 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-611: Improper Restriction of XML External Entity Reference

Source file

maven/io.qameta.allure.plugins/junit-xml-plugin/CVE-2025-52888.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:18:33 +0000.