« Volver al listado

CVE-2025-53103

Estado: AplazadaMedia (5.8)—

JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the OpenTestReportGeneratingListener. If these test reports are published or stored anywhere public, then there is the possibility that a rouge attacker can steal the token and perform elevated actions by impersonating the user or app. This issue as been patched in version 5.13.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-53103",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-53103",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-01T18:50:09.183821Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.8,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 0.6
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "junit-team",
          "product": "junit-framework",
          "versions": [
            {
              "status": "affected",
              "version": ">= 5.12.0, < 5.13.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-01T18:15:25.837",
  "references": [
    {
      "url": "https://github.com/junit-team/junit-framework/commit/d4fc834c8c1c0b3168cd030c13551d1d041f51bc",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/junit-team/junit-framework/security/advisories/GHSA-m43g-m425-p68x",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-312"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the OpenTestReportGeneratingListener. If these test reports are published or stored anywhere public, then there is the possibility that a rouge attacker can steal the token and perform elevated actions by impersonating the user or app. This issue as been patched in version 5.13.2."
    },
    {
      "lang": "es",
      "value": "JUnit es un framework de pruebas para Java y la JVM. Desde la versión 5.12.0 hasta la 5.13.1, la compatibilidad de JUnit con la escritura de archivos XML de Open Test Reporting puede filtrar credenciales de Git. El impacto depende del nivel del token de acceso expuesto a través de OpenTestReportGeneratingListener. Si estos informes de prueba se publican o almacenan en un lugar público, existe la posibilidad de que un atacante malintencionado robe el token y realice acciones elevadas suplantando la identidad del usuario o la aplicación. Este problema se ha corregido en la versión 5.13.2."
    }
  ],
  "lastModified": "2026-06-17T09:37:37.880",
  "sourceIdentifier": "security-advisories@github.com"
}