Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4949

Опубликовано: 21 мая 2025
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

A flaw was found in Eclipse JGit. This vulnerability can allow information disclosure, denial of service, and other security issues via parsing XML files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2org.eclipse.jgitFix deferred
A-MQ Clients 2org.eclipse.jgit.http.apacheFix deferred
Cryostat 3org.eclipse.jgitFix deferred
Cryostat 4org.eclipse.jgitFix deferred
Logging Subsystem for Red Hat OpenShiftorg.eclipse.jgitFix deferred
OpenShift Developer Tools and Servicesjenkins-2-pluginsFix deferred
Red Hat AMQ Broker 7org.eclipse.jgitFix deferred
Red Hat build of Apache Camel for Spring Boot 4org.eclipse.jgitFix deferred
Red Hat build of Apicurio Registry 2org.eclipse.jgitFix deferred
Red Hat build of Apicurio Registry 2org.eclipse.jgit.ssh.jschFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
Дефект:
CWE-827
https://bugzilla.redhat.com/show_bug.cgi?id=2367730JGit: XXE vulnerability in Eclipse JGit

EPSS

Процентиль: 26%
0.00085
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 9.8
nvd
3 месяца назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 9.8
debian
3 месяца назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestP ...

github
3 месяца назад

Eclipse JGit XML External Entity (XXE) Vulnerability

EPSS

Процентиль: 26%
0.00085
Низкий

4.8 Medium

CVSS3