Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4949

Опубликовано: 21 мая 2025
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

A flaw was found in Eclipse JGit. This vulnerability can allow information disclosure, denial of service, and other security issues when parsing XML files.

Отчет

This vulnerability is rated Moderate for Red Hat products. A flaw in Eclipse JGit allows for XML External Entity (XXE) attacks when parsing specially crafted XML files. This can lead to local denial of service in affected Red Hat products that utilize JGit's ManifestParser or AmazonS3 class for git transport. The current 9.8 rating by NVD assumes a default, server-side exploitation path. However, the vulnerability resides in the experimental AmazonS3 transport class within Eclipse JGit, which is not enabled by default and requires non-standard configuration (Attack Complexity: High). Furthermore, exploitation typically occurs via client-side tools (e.g., repo) requiring active user participation (User Interaction: Required), limiting the primary risk to local Denial of Service rather than remote, unauthenticated compromise (Availability: High).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2org.eclipse.jgitAffected
Cryostat 3org.eclipse.jgitAffected
Cryostat 4org.eclipse.jgitNot affected
Logging Subsystem for Red Hat OpenShiftorg.eclipse.jgitAffected
Red Hat AMQ Broker 7org.eclipse.jgitNot affected
Red Hat build of Apicurio Registry 2org.eclipse.jgitAffected
Red Hat build of Apicurio Registry 3org.eclipse.jgitAffected
Red Hat build of OptaPlanner 8org.eclipse.jgitNot affected
Red Hat Data Grid 8org.eclipse.jgitNot affected
Red Hat Fuse 7org.eclipse.jgitWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2367730org.eclipse.jgit: XXE vulnerability in Eclipse JGit

EPSS

Процентиль: 42%
0.00197
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
11 месяцев назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 5.3
nvd
11 месяцев назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 5.3
debian
11 месяцев назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestP ...

suse-cvrf
8 месяцев назад

Security update for eclipse-jgit

github
11 месяцев назад

Eclipse JGit XML External Entity (XXE) Vulnerability

EPSS

Процентиль: 42%
0.00197
Низкий

4.8 Medium

CVSS3