Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4949

Опубликовано: 21 мая 2025
Источник: redhat
CVSS3: 4.8

Описание

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

A flaw was found in Eclipse JGit. This vulnerability can allow information disclosure, denial of service, and other security issues via parsing XML files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2org.eclipse.jgitFix deferred
A-MQ Clients 2org.eclipse.jgit.http.apacheFix deferred
Cryostat 3org.eclipse.jgitFix deferred
Cryostat 4org.eclipse.jgitFix deferred
Logging Subsystem for Red Hat OpenShiftorg.eclipse.jgitFix deferred
OpenShift Developer Tools and Servicesjenkins-2-pluginsFix deferred
Red Hat AMQ Broker 7org.eclipse.jgitFix deferred
Red Hat build of Apache Camel for Spring Boot 4org.eclipse.jgitFix deferred
Red Hat build of Apicurio Registry 2org.eclipse.jgitFix deferred
Red Hat build of Apicurio Registry 2org.eclipse.jgit.ssh.jschFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
Дефект:
CWE-827
https://bugzilla.redhat.com/show_bug.cgi?id=2367730JGit: XXE vulnerability in Eclipse JGit

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
29 дней назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 9.8
nvd
29 дней назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 9.8
debian
29 дней назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestP ...

github
28 дней назад

Eclipse JGit XML External Entity (XXE) Vulnerability

4.8 Medium

CVSS3