JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the OpenTestReportGeneratingListener. If these test reports are published or stored anywhere public, then there is the possibility that a rouge attacker can steal the token and perform elevated actions by impersonating the user or app. This issue as been patched in version 5.13.2.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the OpenTestReportGeneratingListener. If these test reports are published or stored anywhere public, then there is the possibility that a rouge attacker can steal the token and perform elevated actions by impersonating the user or app. This issue as been patched in version 5.13.2. | |
Title | JUnit OpenTestReportGeneratingListener can leak Git credentials | |
Weaknesses | CWE-312 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-01T18:02:39.060Z
Updated: 2025-07-01T18:50:18.904Z
Reserved: 2025-06-25T13:41:23.086Z
Link: CVE-2025-53103

Updated: 2025-07-01T18:50:14.180Z

Status : Awaiting Analysis
Published: 2025-07-01T18:15:25.837
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-53103
