Information Disclosure in JUnit Testing Framework by Vendor
CVE-2025-53103

5.8MEDIUM

Key Information:

Vendor

Junit-team

Vendor
CVE Published:
1 July 2025

What is CVE-2025-53103?

A vulnerability exists within the JUnit testing framework, specifically in versions 5.12.0 through 5.13.1, where support for generating Open Test Reporting XML files can unintentionally expose Git credentials. If these test reports are published or stored in public domains, attackers can potentially steal the access tokens and imitate legitimate users or applications, resulting in unauthorized actions. This flaw has been addressed in version 5.13.2.

Affected Version(s)

junit-framework >= 5.12.0, < 5.13.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53103 : Information Disclosure in JUnit Testing Framework by Vendor