Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1106287: jgit: CVE-2025-4949

    From =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=@21:1/5 to All on Thu May 22 17:40:02 2025
    Source: jgit
    X-Debbugs-CC: team@security.debian.org
    Severity: important
    Tags: security

    Hi,

    The following vulnerability was published for jgit.

    CVE-2025-4949[0]:
    | In Eclipse JGit versions 7.2.0.202503040940-r and older, the
    | ManifestParser class used by the repo command and the AmazonS3 class
    | used to implement the experimental amazons3 git transport protocol
    | allowing to store git pack files in an Amazon S3 bucket, are
    | vulnerable to XML External Entity (XXE) attacks when parsing XML
    | files. This vulnerability can lead to information disclosure, denial
    | of service, and other security issues.

    https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281 https://gitlab.eclipse.org/security/cve-assignement/-/issues/64


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-4949
    https://www.cve.org/CVERecord?id=CVE-2025-4949

    Please adjust the affected versions in the BTS as needed.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Plume
      Mon Jun 9 20:39:48 2025
      from Uk via SSH
    • Michal Wronka
      Mon Jun 9 19:31:41 2025
      from Wroclaw, Poland via Telnet
    • Driswillis156
      Sun Jun 8 22:29:00 2025
      from Nope via SSH
    • Bob Worm
      Sun Jun 8 21:04:22 2025
      from Wales, Uk via Telnet
    • Logan
      Sun Jun 8 15:24:00 2025
      from Adelaide via Telnet
    • Plume
      Sun Jun 8 14:13:27 2025
      from Uk via SSH
    • Bob Worm
      Sun Jun 8 13:48:17 2025
      from Wales, Uk via Telnet
    • Jack
      Sun Jun 8 06:41:19 2025
      from Mississipi via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 489
    Nodes: 16 (2 / 14)
    Uptime: 32:49:19
    Calls: 9,667
    Calls today: 2
    Files: 13,716
    Messages: 6,168,945

© >>> Magnum BBS <<<, 2025