Allure 2 是 Allure Report 的 2.x 分支,Allure Report 是一个多语言测试报告工具。 在 2.39.0 之前,位于 的 辅助函数将攻击者可控的 和 值通过 进行转换,但未进行 HTML 转义,并将结果包装为 Handlebars 的 ,从而禁用了位于 模板中的自动转义机制。 可以直接从精心构造的 JUnit XML 的失败消息(failure messages)和追踪信息(traces)中填充这些字段。此外,在 TRX、xUnit XML、xctest、Allure1 和 Al
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| allure-framework | allure2 | < 2.39.0 |
affected |
| io.qameta.allure | allure-generator | < 2.39.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| allure-framework | allure2 | < 2.39.0 | - |
|
| io.qameta.allure | allure-generator | < 2.39.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet