MEDIUM
GHSA-vrpq-qp53-qv56
Eclipse JGit XML External Entity (XXE) Vulnerability
Quick fix
GHSA-vrpq-qp53-qv56 — org.eclipse.jgit:org.eclipse.jgit: upgrade to the fixed version with the command below.
# pom.xml: bump <version>7.2.1.202505142326-r</version> for org.eclipse.jgit:org.eclipse.jgitDetails
In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.eclipse.jgit:org.eclipse.jgit
Introduced in:
7.2.0.202503040940-rFixed in: 7.2.1.202505142326-rFix
# pom.xml: bump <version>7.2.1.202505142326-r</version> for org.eclipse.jgit:org.eclipse.jgitMaven/org.eclipse.jgit:org.eclipse.jgit
Introduced in:
7.1.0.202411261347-rFixed in: 7.1.1.202505221757-rFix
# pom.xml: bump <version>7.1.1.202505221757-r</version> for org.eclipse.jgit:org.eclipse.jgitMaven/org.eclipse.jgit:org.eclipse.jgit
Introduced in:
7.0.0.202409031743-rFixed in: 7.0.1.202505221510-rFix
# pom.xml: bump <version>7.0.1.202505221510-r</version> for org.eclipse.jgit:org.eclipse.jgitMaven/org.eclipse.jgit:org.eclipse.jgit
Introduced in:
6.1.0.202203080745-rFixed in: 6.10.1.202505221210-rFix
# pom.xml: bump <version>6.10.1.202505221210-r</version> for org.eclipse.jgit:org.eclipse.jgitMaven/org.eclipse.jgit:org.eclipse.jgit
Introduced in:
6.0.0.202110060947-m1Fixed in: 6.0.0.202111291000-rFix
# pom.xml: bump <version>6.0.0.202111291000-r</version> for org.eclipse.jgit:org.eclipse.jgitMaven/org.eclipse.jgit:org.eclipse.jgit
Introduced in:
0Fixed in: 5.13.4.202507202350-rFix
# pom.xml: bump <version>5.13.4.202507202350-r</version> for org.eclipse.jgit:org.eclipse.jgitReferences
- https://nvd.nist.gov/vuln/detail/CVE-2025-4949[ADVISORY]
- https://github.com/eclipse-jgit/jgit[PACKAGE]
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/64[WEB]
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281[WEB]
- https://projects.eclipse.org/projects/technology.jgit/releases/5.13.4[WEB]
- https://projects.eclipse.org/projects/technology.jgit/releases/5.13.5[WEB]
- https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1[WEB]
- https://projects.eclipse.org/projects/technology.jgit/releases/7.0.1[WEB]
- https://projects.eclipse.org/projects/technology.jgit/releases/7.1.1[WEB]
- https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1[WEB]