JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the OpenTestReportGeneratingListener. If these test reports are published or stored anywhere public, then there is the possibility that a rouge attacker can steal the token and perform elevated actions by impersonating the user or app. This issue as been patched in version 5.13.2.
History

Wed, 02 Jul 2025 00:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 01 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Description JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can leak Git credentials. The impact depends on the level of the access token exposed through the OpenTestReportGeneratingListener. If these test reports are published or stored anywhere public, then there is the possibility that a rouge attacker can steal the token and perform elevated actions by impersonating the user or app. This issue as been patched in version 5.13.2.
Title JUnit OpenTestReportGeneratingListener can leak Git credentials
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-01T18:02:39.060Z

Updated: 2025-07-01T18:50:18.904Z

Reserved: 2025-06-25T13:41:23.086Z

Link: CVE-2025-53103

cve-icon Vulnrichment

Updated: 2025-07-01T18:50:14.180Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-01T18:15:25.837

Modified: 2025-07-03T15:14:12.767

Link: CVE-2025-53103

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-07-01T18:02:39Z

Links: CVE-2025-53103 - Bugzilla