GHSA-vrpq-qp53-qv56 · Severity: medium · Ecosystem: maven — Eclipse JGit XML External Entity (XXE) Vulnerability
In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
Conclusion & alert: CVE-2025-4949 is rated Exploit Available (56.9/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.20%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-17 | 0.05% | 0.20% | +0.15% |
| 2 | 2025-11-21 | 0.23% | 0.05% | -0.17% |
| 3 | 2025-11-18 | — | 0.23% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.8 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
1.6 | 3.6 | [email protected] |
GHSA-vrpq-qp53-qv56 · Severity: medium · Ecosystem: maven — Eclipse JGit XML External Entity (XXE) Vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-4949 not yet assigned priority: Debian including 1 source packages (jgit), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2025-4949 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-4949 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2025-4949/ |
ubuntu
|
medium | CVE-2025-4949 medium priority: Ubuntu including 1 source packages (jgit), 9 status rows across 9 suites (bionic, focal, jammy, noble, oracular, plucky, questing, upstream, xenial): needs-triage 7, ignored 2. | https://ubuntu.com/security/CVE-2025-4949 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| eclipse | jgit | < 5.13.4 | cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:* |
| eclipse | jgit | >= 6.0.0, < 6.10.1.202505221210 | cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:* |
| eclipse | jgit | >= 7.0.0, < 7.0.1.202505221510 | cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:* |
| eclipse | jgit | >= 7.1.0, < 7.1.1.202505221757 | cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:* |
| eclipse | jgit | >= 7.2.0, < 7.2.1.202505142326 | cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://gitlab.eclipse.org/security/cve-assignement/-/issues/64 | Issue Tracking Vendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281 | Exploit Issue Tracking |
| https://projects.eclipse.org/projects/technology.jgit/releases/5.13.4 | Release Notes |
| https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1 | Release Notes |
| https://projects.eclipse.org/projects/technology.jgit/releases/7.0.1 | Release Notes |
| https://projects.eclipse.org/projects/technology.jgit/releases/7.1.1 | Release Notes |
| https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1 | Release Notes |