Логотип exploitDog
bind:"GHSA-vrpq-qp53-qv56" OR bind:"CVE-2025-4949"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-vrpq-qp53-qv56" OR bind:"CVE-2025-4949"

Количество 7

Количество 7

github логотип

GHSA-vrpq-qp53-qv56

11 месяцев назад

Eclipse JGit XML External Entity (XXE) Vulnerability

EPSS: Низкий
ubuntu логотип

CVE-2025-4949

11 месяцев назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-4949

11 месяцев назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2025-4949

11 месяцев назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-4949

11 месяцев назад

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestP ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02762-1

8 месяцев назад

Security update for eclipse-jgit

EPSS: Низкий
fstec логотип

BDU:2026-01705

11 месяцев назад

Уязвимость классов ManifestParser и AmazonS3 системы контроля версий Git на языке Java Eclipse JGit, позволяющая нарушителю проводить XXE-атаки

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vrpq-qp53-qv56

Eclipse JGit XML External Entity (XXE) Vulnerability

0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-4949

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-4949

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 4.8
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-4949

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-4949

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestP ...

CVSS3: 5.3
0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02762-1

Security update for eclipse-jgit

0%
Низкий
8 месяцев назад
fstec логотип
BDU:2026-01705

Уязвимость классов ManifestParser и AmazonS3 системы контроля версий Git на языке Java Eclipse JGit, позволяющая нарушителю проводить XXE-атаки

CVSS3: 5.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу