In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
History

Tue, 17 Jun 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse jgit
CPEs cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*
Vendors & Products Eclipse
Eclipse jgit
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 23 May 2025 07:00:00 +0000


Thu, 22 May 2025 02:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 21 May 2025 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 21 May 2025 07:00:00 +0000

Type Values Removed Values Added
Description In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
Title XXE vulnerability in Eclipse JGit
Weaknesses CWE-611
CWE-827
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published: 2025-05-21T06:47:19.777Z

Updated: 2025-05-23T07:00:45.737Z

Reserved: 2025-05-19T07:02:22.381Z

Link: CVE-2025-4949

cve-icon Vulnrichment

Updated: 2025-05-21T10:24:46.428Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-21T07:16:01.397

Modified: 2025-06-17T14:10:34.853

Link: CVE-2025-4949

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-21T06:47:19Z

Links: CVE-2025-4949 - Bugzilla