CVE-2025-4949 Details
Description
In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
A vulnerability allowing XML External Entity (XXE) attacks has been identified in Eclipse JGit versions 7.2.0.202503040940-r and earlier. The issue resides in the ManifestParser class, used by the repo command, and the AmazonS3 class, which implements the experimental amazons3 git transport protocol for storing git pack files in an Amazon S3 bucket. Both classes parse XML files without properly disabling external entity processing, potentially leading to information disclosure, denial of service, and other security issues.
Users can upgrade to Eclipse JGit versions 7.2.1.202505221210-r, 7.0.1.202505221510-r, 7.1.1.202505221757-r or 6.10.1.202505221210-r, all of which include the necessary fix. Instructions for downloading these versions are available on the Eclipse JGit release page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281 | CISA-ADP | ExploitIssue Tracking |
| https://gitlab.eclipse.org/security/cve-assignement/-/issues/64 | [email protected] | Issue TrackingVendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281 | [email protected] | ExploitIssue Tracking |
| https://projects.eclipse.org/projects/technology.jgit/releases/5.13.4 | [email protected] | Release Notes |
| https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1 | [email protected] | Release Notes |
| https://projects.eclipse.org/projects/technology.jgit/releases/7.0.1 | [email protected] | Release Notes |
| https://projects.eclipse.org/projects/technology.jgit/releases/7.1.1 | [email protected] | Release Notes |
| https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1 | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
| CWE-827 | Improper Control of Document Type Definition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eclipse jgit | < 5.13.4 >= 6.0.0, < 6.10.1.202505221210 >= 7.0.0, < 7.0.1.202505221510 >= 7.1.0, < 7.1.1.202505221757 >= 7.2.0, < 7.2.1.202505142326 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 5, 2026 | Modified Analysis | [email protected] |
| Oct 16, 2025 | Modified Analysis | [email protected] |
| Oct 14, 2025 | CVE Modified | [email protected] |
| Aug 25, 2025 | Reanalysis | [email protected] |
| Jun 17, 2025 | Initial Analysis | [email protected] |
| May 23, 2025 | CVE Modified | [email protected] |
| May 21, 2025 | CVE Modified | CISA-ADP |
| May 21, 2025 | New CVE Received | [email protected] |