VYPR
Medium severity5.3NVD Advisory· Published May 21, 2025· Updated Jun 17, 2026

CVE-2025-4949

CVE-2025-4949

Description

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.eclipse.jgit:org.eclipse.jgitMaven
>= 7.2.0.202503040940-r, < 7.2.1.202505142326-r7.2.1.202505142326-r
org.eclipse.jgit:org.eclipse.jgitMaven
>= 7.1.0.202411261347-r, < 7.1.1.202505221757-r7.1.1.202505221757-r
org.eclipse.jgit:org.eclipse.jgitMaven
>= 7.0.0.202409031743-r, < 7.0.1.202505221510-r7.0.1.202505221510-r
org.eclipse.jgit:org.eclipse.jgitMaven
>= 6.1.0.202203080745-r, < 6.10.1.202505221210-r6.10.1.202505221210-r
org.eclipse.jgit:org.eclipse.jgitMaven
>= 6.0.0.202110060947-m1, < 6.0.0.202111291000-r6.0.0.202111291000-r
org.eclipse.jgit:org.eclipse.jgitMaven
< 5.13.4.202507202350-r5.13.4.202507202350-r

Affected products

49

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.