Eclipse Jgit vulnerabilities
3 known vulnerabilities affecting eclipse/jgit.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-4949MEDIUMCVSS 6.8fixed in 5.13.4≥ 6.0.0, < 6.10.1.202505221210+3 more2025-05-21
CVE-2025-4949 [MEDIUM] CWE-611 CVE-2025-4949: In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo c
In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can
nvd
CVE-2023-4759HIGHCVSS 8.8fixed in 5.13.3.202401111512-r≥ 6.6.0, < 6.6.0.202305301015+1 more2023-09-12
CVE-2023-4759 [HIGH] CWE-59 CVE-2023-4759: Arbitrary File Overwrite in Eclipse JGit <= 6.6.0
In Eclipse JGit, all versions <= 6.6.0.2023053010
Arbitrary File Overwrite in Eclipse JGit <= 6.6.0
In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repos
nvdosv
CVE-2014-9390CRITICALCVSS 9.8PoCfixed in 3.4.2≥ 3.5.0, < 3.5.32020-02-12
CVE-2014-9390 [CRITICAL] CWE-20 CVE-2014-9390: Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allo
nvdosv