CVE-2025-4949

EUVD-2025-15988
In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53.2%
Affected Products (NVD)
VendorProductVersion
eclipsejgit
𝑥
< 5.13.4
eclipsejgit
6.0.0 ≤
𝑥
< 6.10.1.202505221210
eclipsejgit
7.0.0 ≤
𝑥
< 7.0.1.202505221510
eclipsejgit
7.1.0 ≤
𝑥
< 7.1.1.202505221757
eclipsejgit
7.2.0 ≤
𝑥
< 7.2.1.202505142326
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jgit
bookworm
no-dsa
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jgit
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage
xenial
needs-triage