Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19057 | Allure Report allows Improper XXE Restriction via DocumentBuilderFactory |
Github GHSA |
GHSA-h7qf-qmf3-85qg | Allure Report allows Improper XXE Restriction via DocumentBuilderFactory |
Tue, 24 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Jun 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser (`DocumentBuilderFactory`) and allows external entity expansion when processing test result .xml files. This allows attackers to read arbitrary files from the file system and potentially trigger server-side request forgery (SSRF). Version 2.34.1 contains a patch for the issue. | |
| Title | Allure 2's xunit-xml-plugin Vulnerable to Improper XXE Restriction | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-24T19:56:50.479Z
Reserved: 2025-06-20T17:42:25.709Z
Link: CVE-2025-52888
Updated: 2025-06-24T19:56:30.244Z
Status : Deferred
Published: 2025-06-24T20:15:26.700
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-52888
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA