CVE-2025-4949CWE-611CWE-827

XXE vulnerability in Eclipse JGit

Medium · published May 21, 2025

CVSS v4.0
6.8
EPSS
1%
Percentile
53.3
In the wild
Unconfirmed
What it is

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

The record
Technical detail
CVSS v4.0
6.8 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green
EPSS
0.00771 · 53.3th percentile
Weaknesses
CWE-611 · Improper Restriction of XML External Entity Reference; CWE-827 · Improper Control of Document Type Definition
Published
2025-05-21T06:47Z
EPSS history
Timeline
  • 21 MAY 06:47Z
    XXE vulnerability in Eclipse JGit
    cvelistv5