CVE-2025-4949

Aliases:GHSA-vrpq-qp53-qv56
Analyzed
Published: 21 May 2025, 06:47
Last modified:14 Oct 2025, 06:30

Vulnerability Summary

Overall Risk (default)
medium
37/100
CVSS Score
6.8 MEDIUM
v4.0 (cve.org)
EPSS Score
0.2% LOW
0% probability +0.11%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

21 May 2025, 06:47
Published
Vulnerability first disclosed
14 Oct 2025, 06:30
Last Modified
Vulnerability information updated

Description

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

CVSS Metrics

  • v4.0MEDIUMScore: 6.8CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green
  • v4.0MEDIUMScore: 6.8CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Green
  • v4.0MEDIUMScore: 6.8CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.20% Percentile: 42%

Techniques & Countermeasures

  • CWE-611Improper Restriction of XML External Entity Reference

    The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

  • CWE-827Improper Control of Document Type Definition

    The product does not restrict a reference to a Document Type Definition (DTD) to the intended control sphere. This might allow attackers to reference arbitrary DTDs, possibly causing the product to expose files, consume excessive system resources, or execute arbitrary http requests on behalf of the attacker.

Affected Systems

  • eclipse jgiteclipse jgit

    ≥ 7.2.0, < 7.2.1.202505142326-r | ≥ 7.1.0, < 7.1.1.202505221757-r | ≥ 7.0.0, < 7.0.1.202505221510-r | < 5.13.4.202507202350-r | ≥ 6.0.0, < 6.10.1.202505221210-r

  • eclipsejgit

    < 5.13.4 | ≥ 6.0.0, < 6.10.1.202505221210 | ≥ 7.0.0, < 7.0.1.202505221510 | ≥ 7.1.0, < 7.1.1.202505221757 | ≥ 7.2.0, < 7.2.1.202505142326

  • org.eclipse.jgitorg.eclipse.jgit

    ≥ 7.2.0.202503040940-r, < 7.2.1.202505142326-r | ≥ 7.1.0.202411261347-r, < 7.1.1.202505221757-r | ≥ 7.0.0.202409031743-r, < 7.0.1.202505221510-r | ≥ 6.1.0.202203080745-r, < 6.10.1.202505221210-r | ≥ 6.0.0.202110060947-m1, < 6.0.0.202111291000-r | < 5.13.4.202507202350-r

References (10)