CVE-2025-4949
Estado: AnalizadaMedia (6.8)—
In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Green
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.81%
- Percentil entre todas las CVEs puntuadas: 55
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-611, CWE-827
- CWE-611
Referencias
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/64
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281
- https://projects.eclipse.org/projects/technology.jgit/releases/5.13.4
- https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1
- https://projects.eclipse.org/projects/technology.jgit/releases/7.0.1
- https://projects.eclipse.org/projects/technology.jgit/releases/7.1.1
- https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-4949",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-4949",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-21T10:22:48.944398Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.6
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"cvssData": {
"Safety": "NEGLIGIBLE",
"version": "4.0",
"Recovery": "USER",
"baseScore": 6.8,
"Automatable": "YES",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "DIFFUSE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Green",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "GREEN",
"userInteraction": "ACTIVE",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "LOW",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "emo@eclipse.org",
"affectedData": [
{
"repo": "https://github.com/eclipse-jgit/jgit",
"vendor": "Eclipse JGit",
"product": "Eclipse JGit",
"versions": [
{
"status": "affected",
"version": "7.2.0",
"lessThan": "7.2.1.202505142326-r",
"versionType": "osgi"
},
{
"status": "affected",
"version": "7.1.0",
"lessThan": "7.1.1.202505221757-r",
"versionType": "osgi"
},
{
"status": "affected",
"version": "7.0.0",
"lessThan": "7.0.1.202505221510-r",
"versionType": "osgi"
},
{
"status": "affected",
"version": "0",
"lessThan": "5.13.4.202507202350-r",
"versionType": "osgi"
},
{
"status": "affected",
"version": "6.0.0",
"lessThan": "6.10.1.202505221210-r",
"versionType": "osgi"
}
],
"collectionURL": "https://projects.eclipse.org",
"defaultStatus": "unaffected"
},
{
"repo": "https://github.com/eclipse-jgit/jgit",
"vendor": "Eclipse JGit",
"product": "Eclipse JGit",
"versions": [
{
"status": "affected",
"version": "7.2.0",
"lessThan": "7.2.1.202505142326-r",
"versionType": "osgi"
},
{
"status": "affected",
"version": "7.1.0",
"lessThan": "7.1.1.202505221757-r",
"versionType": "osgi"
},
{
"status": "affected",
"version": "7.0.0",
"lessThan": "7.0.1.202505221510-r",
"versionType": "osgi"
},
{
"status": "affected",
"version": "0",
"lessThan": "5.13.4.202507202350-r",
"versionType": "osgi"
},
{
"status": "affected",
"version": "6.0.0",
"lessThan": "6.10.1.202505221210-r",
"versionType": "osgi"
}
],
"packageName": "pkg:maven/org.eclipse.jgit/org.eclipse.jgit",
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-05-21T07:16:01.397",
"references": [
{
"url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/64",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "emo@eclipse.org"
},
{
"url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281",
"tags": [
"Exploit",
"Issue Tracking"
],
"source": "emo@eclipse.org"
},
{
"url": "https://projects.eclipse.org/projects/technology.jgit/releases/5.13.4",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.0.1",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.1.1",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1",
"tags": [
"Release Notes"
],
"source": "emo@eclipse.org"
},
{
"url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281",
"tags": [
"Exploit",
"Issue Tracking"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"description": [
{
"lang": "en",
"value": "CWE-611"
},
{
"lang": "en",
"value": "CWE-827"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-611"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues."
},
{
"lang": "es",
"value": "En las versiones 7.2.0.202503040940-r y anteriores de Eclipse JGit, la clase ManifestParser, utilizada por el comando repo, y la clase AmazonS3, utilizada para implementar el protocolo experimental de transporte de Git amazons3, que permite almacenar archivos de paquetes de Git en un bucket de Amazon S3, son vulnerables a ataques de Entidad Externa XML (XXE) al analizar archivos XML. Esta vulnerabilidad puede provocar divulgación de información, denegación de servicio y otros problemas de seguridad."
}
],
"lastModified": "2026-06-17T09:34:22.633",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA83AF58-95B9-4502-B31D-E4FDE3AE38B5",
"versionEndExcluding": "5.13.4"
},
{
"criteria": "cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "564D2570-3C49-420B-A01D-0803E7EFD1CD",
"versionEndExcluding": "6.10.1.202505221210",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3FEEF05C-0772-4BAF-A4AB-A87CFE32121C",
"versionEndExcluding": "7.0.1.202505221510",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5B0B7A0-8785-4C21-96F8-98EDD7A23D50",
"versionEndExcluding": "7.1.1.202505221757",
"versionStartIncluding": "7.1.0"
},
{
"criteria": "cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D70B5F8-067E-434D-8EC5-33301A264288",
"versionEndExcluding": "7.2.1.202505142326",
"versionStartIncluding": "7.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "emo@eclipse.org"
}