Search

Find a vulnerability

Search criteria

    6 vulnerabilities found for jgit by eclipse

    CVE-2025-4949 (GCVE-0-2025-4949)

    Vulnerability from nvd – Published: 2025-05-21 06:47 – Updated: 2025-10-14 06:30
    VLAI
    Title
    XXE vulnerability in Eclipse JGit
    Summary
    In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-21 10:22 UTC
    CWE
    • CWE-611 - Improper Restriction of XML External Entity Reference
    • CWE-827 - Improper Control of Document Type Definition
    Impacted products
    Vendor Product Version
    Eclipse JGit Eclipse JGit Affected: 7.2.0 , < 7.2.1.202505142326-r (osgi)
    Affected: 7.1.0 , < 7.1.1.202505221757-r (osgi)
    Affected: 7.0.0 , < 7.0.1.202505221510-r (osgi)
    Affected: 0 , < 5.13.4.202507202350-r (osgi)
    Affected: 6.0.0 , < 6.10.1.202505221210-r (osgi)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4949",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-21T10:22:48.944398Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-21T10:24:58.815Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://projects.eclipse.org",
              "defaultStatus": "unaffected",
              "product": "Eclipse JGit",
              "repo": "https://github.com/eclipse-jgit/jgit",
              "vendor": "Eclipse JGit",
              "versions": [
                {
                  "lessThan": "7.2.1.202505142326-r",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "7.1.1.202505221757-r",
                  "status": "affected",
                  "version": "7.1.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "7.0.1.202505221510-r",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "5.13.4.202507202350-r",
                  "status": "affected",
                  "version": "0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "6.10.1.202505221210-r",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "osgi"
                }
              ]
            },
            {
              "collectionURL": "https://repo.maven.apache.org/maven2",
              "defaultStatus": "unaffected",
              "packageName": "pkg:maven/org.eclipse.jgit/org.eclipse.jgit",
              "product": "Eclipse JGit",
              "repo": "https://github.com/eclipse-jgit/jgit",
              "vendor": "Eclipse JGit",
              "versions": [
                {
                  "lessThan": "7.2.1.202505142326-r",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "7.1.1.202505221757-r",
                  "status": "affected",
                  "version": "7.1.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "7.0.1.202505221510-r",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "5.13.4.202507202350-r",
                  "status": "affected",
                  "version": "0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "6.10.1.202505221210-r",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "osgi"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Simon Gerst (intrigus-lgtm) https://intrigus.org"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In Eclipse JGit versions 7.2.0.202503040940-r and older, the \u003ccode\u003eManifestParser\u003c/code\u003e class used by the \u003ccode\u003erepo\u003c/code\u003e command and the \u003ccode\u003eAmazonS3\u003c/code\u003e class used to implement the experimental \u003ccode\u003eamazons3\u003c/code\u003e git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues."
                }
              ],
              "value": "In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-201",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-201 Serialized Data External Linking"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "USER",
                "Safety": "NEGLIGIBLE",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "GREEN",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "LOW"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL."
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-611",
                  "description": "CWE-611 Improper Restriction of XML External Entity Reference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-827",
                  "description": "CWE-827 Improper Control of Document Type Definition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-14T06:30:04.660Z",
            "orgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
            "shortName": "eclipse"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.1.1"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.0.1"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/64"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/5.13.4"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "XXE vulnerability in Eclipse JGit",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
        "assignerShortName": "eclipse",
        "cveId": "CVE-2025-4949",
        "datePublished": "2025-05-21T06:47:19.777Z",
        "dateReserved": "2025-05-19T07:02:22.381Z",
        "dateUpdated": "2025-10-14T06:30:04.660Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-4759 (GCVE-0-2023-4759)

    Vulnerability from nvd – Published: 2023-09-12 09:12 – Updated: 2024-08-02 07:37
    VLAI
    Title
    Improper handling of case insensitive filesystems in Eclipse JGit allows arbitrary file write
    Summary
    Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem. This can happen on checkout (DirCacheCheckout), merge (ResolveMerger via its WorkingTreeUpdater), pull (PullCommand using merge), and when applying a patch (PatchApplier). This can be exploited for remote code execution (RCE), for instance if the file written outside the working tree is a git filter that gets executed on a subsequent git command. The issue occurs only on case-insensitive filesystems, like the default filesystems on Windows and macOS. The user performing the clone or checkout must have the rights to create symbolic links for the problem to occur, and symbolic links must be enabled in the git configuration. Setting git configuration option core.symlinks = false before checking out avoids the problem. The issue was fixed in Eclipse JGit version 6.6.1.202309021850-r and 6.7.0.202309050840-r, available via Maven Central https://repo1.maven.org/maven2/org/eclipse/jgit/  and repo.eclipse.org https://repo.eclipse.org/content/repositories/jgit-releases/ . A backport is available in 5.13.3 starting from 5.13.3.202401111512-r. The JGit maintainers would like to thank RyotaK for finding and reporting this issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-19 03:55 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    • CWE-178 - Improper Handling of Case Sensitivity
    Impacted products
    Vendor Product Version
    Eclipse Foundation Eclipse JGit Affected: 0.0.0 , ≤ 6.6.0.202305301015-r (semver)
    Unaffected: 5.13.3.202401111512-r
    Create a notification for this product.
    eclipse jgit Affected: 0 , ≤ 6.6.0.202305301015-r (semver)
        cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eclipse jgit Unaffected: 5.13.3.202401111512-r
        cpe:2.3:a:eclipse:jgit:5.13.3.202401111512-r:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-09-12 10:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "jgit",
                "vendor": "eclipse",
                "versions": [
                  {
                    "lessThanOrEqual": "6.6.0.202305301015-r",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eclipse:jgit:5.13.3.202401111512-r:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "jgit",
                "vendor": "eclipse",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "5.13.3.202401111512-r"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4759",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-19T03:55:38.083883Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-19T13:51:38.023Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:37:59.574Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/11"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://projects.eclipse.org/projects/technology.jgit/releases/6.6.1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.eclipse.org/c/jgit/jgit.git/commit/?id=9072103f3b3cf64dd12ad2949836ab98f62dabf1"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://git.eclipse.org/c/jgit/jgit.git/",
              "defaultStatus": "unaffected",
              "product": "Eclipse JGit",
              "vendor": "Eclipse Foundation",
              "versions": [
                {
                  "lessThanOrEqual": "6.6.0.202305301015-r",
                  "status": "affected",
                  "version": "0.0.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "  5.13.3.202401111512-r"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "RyotaK"
            }
          ],
          "datePublic": "2023-09-12T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eArbitrary File Overwrite in Eclipse JGit \u0026lt;= 6.6.0\u003c/p\u003e\u003cp\u003eIn Eclipse JGit, all versions \u0026lt;= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem.\u003c/p\u003e\u003cp\u003eThis can happen on checkout (\u003ccode\u003eDirCacheCheckout\u003c/code\u003e), merge (\u003ccode\u003eResolveMerger\u003c/code\u003e\u0026nbsp;via its \u003ccode\u003eWorkingTreeUpdater\u003c/code\u003e), pull (\u003ccode\u003ePullCommand\u003c/code\u003e\u0026nbsp;using merge), and when applying a patch (\u003ccode\u003ePatchApplier\u003c/code\u003e). This can be exploited for remote code execution (RCE), for instance if the file written outside the working tree is a git filter that gets executed on a subsequent git command.\u003c/p\u003e\u003cp\u003eThe issue occurs only on case-\u003cstrong\u003ein\u003c/strong\u003esensitive filesystems, like the default filesystems on Windows and macOS. The user performing the clone or checkout must have the rights to create symbolic links for the problem to occur, and symbolic links must be enabled in the git configuration.\u003c/p\u003e\u003cp\u003eSetting git configuration option \u003ccode\u003ecore.symlinks = false\u003c/code\u003e\u0026nbsp;before checking out avoids the problem.\u003c/p\u003e\u003cp\u003eThe issue was fixed in Eclipse JGit version 6.6.1.202309021850-r and 6.7.0.202309050840-r, available via \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://repo1.maven.org/maven2/org/eclipse/jgit/\"\u003eMaven Central\u003c/a\u003e\u0026nbsp;and \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://repo.eclipse.org/content/repositories/jgit-releases/\"\u003erepo.eclipse.org\u003c/a\u003e. A backport is available in 5.13.3 starting from  5.13.3.202401111512-r.\u003cbr\u003e\u003c/p\u003e\u003cp\u003eThe JGit maintainers would like to thank RyotaK for finding and reporting this issue.\u003cbr\u003e\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "Arbitrary File Overwrite in Eclipse JGit \u003c= 6.6.0\n\nIn Eclipse JGit, all versions \u003c= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem.\n\nThis can happen on checkout (DirCacheCheckout), merge (ResolveMerger\u00a0via its WorkingTreeUpdater), pull (PullCommand\u00a0using merge), and when applying a patch (PatchApplier). This can be exploited for remote code execution (RCE), for instance if the file written outside the working tree is a git filter that gets executed on a subsequent git command.\n\nThe issue occurs only on case-insensitive filesystems, like the default filesystems on Windows and macOS. The user performing the clone or checkout must have the rights to create symbolic links for the problem to occur, and symbolic links must be enabled in the git configuration.\n\nSetting git configuration option core.symlinks = false\u00a0before checking out avoids the problem.\n\nThe issue was fixed in Eclipse JGit version 6.6.1.202309021850-r and 6.7.0.202309050840-r, available via  Maven Central https://repo1.maven.org/maven2/org/eclipse/jgit/ \u00a0and  repo.eclipse.org https://repo.eclipse.org/content/repositories/jgit-releases/ . A backport is available in 5.13.3 starting from  5.13.3.202401111512-r.\n\n\nThe JGit maintainers would like to thank RyotaK for finding and reporting this issue.\n\n\n\n"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-132",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-132 Symlink Attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-178",
                  "description": "CWE-178 Improper Handling of Case Sensitivity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-12T15:21:24.101Z",
            "orgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
            "shortName": "eclipse"
          },
          "references": [
            {
              "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/11"
            },
            {
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/6.6.1"
            },
            {
              "url": "https://git.eclipse.org/c/jgit/jgit.git/commit/?id=9072103f3b3cf64dd12ad2949836ab98f62dabf1"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Improper handling of case insensitive filesystems in Eclipse JGit allows arbitrary file write",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eSetting git configuration option \u003ccode\u003ecore.symlinks = false\u003c/code\u003e\u0026nbsp;before checking out avoids the problem.\u003c/p\u003e"
                }
              ],
              "value": "Setting git configuration option core.symlinks = false\u00a0before checking out avoids the problem.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
        "assignerShortName": "eclipse",
        "cveId": "CVE-2023-4759",
        "datePublished": "2023-09-12T09:12:10.254Z",
        "dateReserved": "2023-09-04T16:06:00.689Z",
        "dateUpdated": "2024-08-02T07:37:59.574Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-9390 (GCVE-0-2014-9390)

    Vulnerability from nvd – Published: 2020-02-12 01:58 – Updated: 2024-08-06 13:40
    VLAI
    Summary
    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Date Public
    2014-12-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T13:40:25.038Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://news.ycombinator.com/item?id=8769667"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://article.gmane.org/gmane.linux.kernel/1853266"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://mercurial.selenic.com/wiki/WhatsNew"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://support.apple.com/kb/HT204147"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/blog/1938-git-client-vulnerability-announced"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1031404"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://libgit2.org/security/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2014-12-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-09-09T17:07:52.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://news.ycombinator.com/item?id=8769667"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://article.gmane.org/gmane.linux.kernel/1853266"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://mercurial.selenic.com/wiki/WhatsNew"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://support.apple.com/kb/HT204147"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/blog/1938-git-client-vulnerability-announced"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://securitytracker.com/id?1031404"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://libgit2.org/security/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2014-9390",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://news.ycombinator.com/item?id=8769667",
                  "refsource": "MISC",
                  "url": "https://news.ycombinator.com/item?id=8769667"
                },
                {
                  "name": "http://article.gmane.org/gmane.linux.kernel/1853266",
                  "refsource": "MISC",
                  "url": "http://article.gmane.org/gmane.linux.kernel/1853266"
                },
                {
                  "name": "http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html",
                  "refsource": "MISC",
                  "url": "http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html"
                },
                {
                  "name": "http://mercurial.selenic.com/wiki/WhatsNew",
                  "refsource": "MISC",
                  "url": "http://mercurial.selenic.com/wiki/WhatsNew"
                },
                {
                  "name": "http://support.apple.com/kb/HT204147",
                  "refsource": "MISC",
                  "url": "http://support.apple.com/kb/HT204147"
                },
                {
                  "name": "https://github.com/blog/1938-git-client-vulnerability-announced",
                  "refsource": "MISC",
                  "url": "https://github.com/blog/1938-git-client-vulnerability-announced"
                },
                {
                  "name": "http://securitytracker.com/id?1031404",
                  "refsource": "MISC",
                  "url": "http://securitytracker.com/id?1031404"
                },
                {
                  "name": "https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915",
                  "refsource": "MISC",
                  "url": "https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915"
                },
                {
                  "name": "https://libgit2.org/security/",
                  "refsource": "MISC",
                  "url": "https://libgit2.org/security/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2014-9390",
        "datePublished": "2020-02-12T01:58:27.000Z",
        "dateReserved": "2014-12-17T00:00:00.000Z",
        "dateUpdated": "2024-08-06T13:40:25.038Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-4949 (GCVE-0-2025-4949)

    Vulnerability from cvelistv5 – Published: 2025-05-21 06:47 – Updated: 2025-10-14 06:30
    VLAI
    Title
    XXE vulnerability in Eclipse JGit
    Summary
    In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-21 10:22 UTC
    CWE
    • CWE-611 - Improper Restriction of XML External Entity Reference
    • CWE-827 - Improper Control of Document Type Definition
    Impacted products
    Vendor Product Version
    Eclipse JGit Eclipse JGit Affected: 7.2.0 , < 7.2.1.202505142326-r (osgi)
    Affected: 7.1.0 , < 7.1.1.202505221757-r (osgi)
    Affected: 7.0.0 , < 7.0.1.202505221510-r (osgi)
    Affected: 0 , < 5.13.4.202507202350-r (osgi)
    Affected: 6.0.0 , < 6.10.1.202505221210-r (osgi)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4949",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-21T10:22:48.944398Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-21T10:24:58.815Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://projects.eclipse.org",
              "defaultStatus": "unaffected",
              "product": "Eclipse JGit",
              "repo": "https://github.com/eclipse-jgit/jgit",
              "vendor": "Eclipse JGit",
              "versions": [
                {
                  "lessThan": "7.2.1.202505142326-r",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "7.1.1.202505221757-r",
                  "status": "affected",
                  "version": "7.1.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "7.0.1.202505221510-r",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "5.13.4.202507202350-r",
                  "status": "affected",
                  "version": "0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "6.10.1.202505221210-r",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "osgi"
                }
              ]
            },
            {
              "collectionURL": "https://repo.maven.apache.org/maven2",
              "defaultStatus": "unaffected",
              "packageName": "pkg:maven/org.eclipse.jgit/org.eclipse.jgit",
              "product": "Eclipse JGit",
              "repo": "https://github.com/eclipse-jgit/jgit",
              "vendor": "Eclipse JGit",
              "versions": [
                {
                  "lessThan": "7.2.1.202505142326-r",
                  "status": "affected",
                  "version": "7.2.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "7.1.1.202505221757-r",
                  "status": "affected",
                  "version": "7.1.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "7.0.1.202505221510-r",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "5.13.4.202507202350-r",
                  "status": "affected",
                  "version": "0",
                  "versionType": "osgi"
                },
                {
                  "lessThan": "6.10.1.202505221210-r",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "osgi"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Simon Gerst (intrigus-lgtm) https://intrigus.org"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In Eclipse JGit versions 7.2.0.202503040940-r and older, the \u003ccode\u003eManifestParser\u003c/code\u003e class used by the \u003ccode\u003erepo\u003c/code\u003e command and the \u003ccode\u003eAmazonS3\u003c/code\u003e class used to implement the experimental \u003ccode\u003eamazons3\u003c/code\u003e git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues."
                }
              ],
              "value": "In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-201",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-201 Serialized Data External Linking"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "USER",
                "Safety": "NEGLIGIBLE",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "GREEN",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "LOW"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL."
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-611",
                  "description": "CWE-611 Improper Restriction of XML External Entity Reference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-827",
                  "description": "CWE-827 Improper Control of Document Type Definition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-14T06:30:04.660Z",
            "orgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
            "shortName": "eclipse"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.1.1"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/7.0.1"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/64"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/5.13.4"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "XXE vulnerability in Eclipse JGit",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
        "assignerShortName": "eclipse",
        "cveId": "CVE-2025-4949",
        "datePublished": "2025-05-21T06:47:19.777Z",
        "dateReserved": "2025-05-19T07:02:22.381Z",
        "dateUpdated": "2025-10-14T06:30:04.660Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-4759 (GCVE-0-2023-4759)

    Vulnerability from cvelistv5 – Published: 2023-09-12 09:12 – Updated: 2024-08-02 07:37
    VLAI
    Title
    Improper handling of case insensitive filesystems in Eclipse JGit allows arbitrary file write
    Summary
    Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem. This can happen on checkout (DirCacheCheckout), merge (ResolveMerger via its WorkingTreeUpdater), pull (PullCommand using merge), and when applying a patch (PatchApplier). This can be exploited for remote code execution (RCE), for instance if the file written outside the working tree is a git filter that gets executed on a subsequent git command. The issue occurs only on case-insensitive filesystems, like the default filesystems on Windows and macOS. The user performing the clone or checkout must have the rights to create symbolic links for the problem to occur, and symbolic links must be enabled in the git configuration. Setting git configuration option core.symlinks = false before checking out avoids the problem. The issue was fixed in Eclipse JGit version 6.6.1.202309021850-r and 6.7.0.202309050840-r, available via Maven Central https://repo1.maven.org/maven2/org/eclipse/jgit/  and repo.eclipse.org https://repo.eclipse.org/content/repositories/jgit-releases/ . A backport is available in 5.13.3 starting from 5.13.3.202401111512-r. The JGit maintainers would like to thank RyotaK for finding and reporting this issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-19 03:55 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    • CWE-178 - Improper Handling of Case Sensitivity
    Impacted products
    Vendor Product Version
    Eclipse Foundation Eclipse JGit Affected: 0.0.0 , ≤ 6.6.0.202305301015-r (semver)
    Unaffected: 5.13.3.202401111512-r
    Create a notification for this product.
    eclipse jgit Affected: 0 , ≤ 6.6.0.202305301015-r (semver)
        cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*
    Create a notification for this product.
    eclipse jgit Unaffected: 5.13.3.202401111512-r
        cpe:2.3:a:eclipse:jgit:5.13.3.202401111512-r:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-09-12 10:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "jgit",
                "vendor": "eclipse",
                "versions": [
                  {
                    "lessThanOrEqual": "6.6.0.202305301015-r",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:eclipse:jgit:5.13.3.202401111512-r:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "jgit",
                "vendor": "eclipse",
                "versions": [
                  {
                    "status": "unaffected",
                    "version": "5.13.3.202401111512-r"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4759",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-19T03:55:38.083883Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-19T13:51:38.023Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:37:59.574Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/11"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://projects.eclipse.org/projects/technology.jgit/releases/6.6.1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.eclipse.org/c/jgit/jgit.git/commit/?id=9072103f3b3cf64dd12ad2949836ab98f62dabf1"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://git.eclipse.org/c/jgit/jgit.git/",
              "defaultStatus": "unaffected",
              "product": "Eclipse JGit",
              "vendor": "Eclipse Foundation",
              "versions": [
                {
                  "lessThanOrEqual": "6.6.0.202305301015-r",
                  "status": "affected",
                  "version": "0.0.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "  5.13.3.202401111512-r"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "RyotaK"
            }
          ],
          "datePublic": "2023-09-12T10:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eArbitrary File Overwrite in Eclipse JGit \u0026lt;= 6.6.0\u003c/p\u003e\u003cp\u003eIn Eclipse JGit, all versions \u0026lt;= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem.\u003c/p\u003e\u003cp\u003eThis can happen on checkout (\u003ccode\u003eDirCacheCheckout\u003c/code\u003e), merge (\u003ccode\u003eResolveMerger\u003c/code\u003e\u0026nbsp;via its \u003ccode\u003eWorkingTreeUpdater\u003c/code\u003e), pull (\u003ccode\u003ePullCommand\u003c/code\u003e\u0026nbsp;using merge), and when applying a patch (\u003ccode\u003ePatchApplier\u003c/code\u003e). This can be exploited for remote code execution (RCE), for instance if the file written outside the working tree is a git filter that gets executed on a subsequent git command.\u003c/p\u003e\u003cp\u003eThe issue occurs only on case-\u003cstrong\u003ein\u003c/strong\u003esensitive filesystems, like the default filesystems on Windows and macOS. The user performing the clone or checkout must have the rights to create symbolic links for the problem to occur, and symbolic links must be enabled in the git configuration.\u003c/p\u003e\u003cp\u003eSetting git configuration option \u003ccode\u003ecore.symlinks = false\u003c/code\u003e\u0026nbsp;before checking out avoids the problem.\u003c/p\u003e\u003cp\u003eThe issue was fixed in Eclipse JGit version 6.6.1.202309021850-r and 6.7.0.202309050840-r, available via \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://repo1.maven.org/maven2/org/eclipse/jgit/\"\u003eMaven Central\u003c/a\u003e\u0026nbsp;and \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://repo.eclipse.org/content/repositories/jgit-releases/\"\u003erepo.eclipse.org\u003c/a\u003e. A backport is available in 5.13.3 starting from  5.13.3.202401111512-r.\u003cbr\u003e\u003c/p\u003e\u003cp\u003eThe JGit maintainers would like to thank RyotaK for finding and reporting this issue.\u003cbr\u003e\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "Arbitrary File Overwrite in Eclipse JGit \u003c= 6.6.0\n\nIn Eclipse JGit, all versions \u003c= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem.\n\nThis can happen on checkout (DirCacheCheckout), merge (ResolveMerger\u00a0via its WorkingTreeUpdater), pull (PullCommand\u00a0using merge), and when applying a patch (PatchApplier). This can be exploited for remote code execution (RCE), for instance if the file written outside the working tree is a git filter that gets executed on a subsequent git command.\n\nThe issue occurs only on case-insensitive filesystems, like the default filesystems on Windows and macOS. The user performing the clone or checkout must have the rights to create symbolic links for the problem to occur, and symbolic links must be enabled in the git configuration.\n\nSetting git configuration option core.symlinks = false\u00a0before checking out avoids the problem.\n\nThe issue was fixed in Eclipse JGit version 6.6.1.202309021850-r and 6.7.0.202309050840-r, available via  Maven Central https://repo1.maven.org/maven2/org/eclipse/jgit/ \u00a0and  repo.eclipse.org https://repo.eclipse.org/content/repositories/jgit-releases/ . A backport is available in 5.13.3 starting from  5.13.3.202401111512-r.\n\n\nThe JGit maintainers would like to thank RyotaK for finding and reporting this issue.\n\n\n\n"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-132",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-132 Symlink Attack"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59 Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-178",
                  "description": "CWE-178 Improper Handling of Case Sensitivity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-12T15:21:24.101Z",
            "orgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
            "shortName": "eclipse"
          },
          "references": [
            {
              "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/11"
            },
            {
              "url": "https://projects.eclipse.org/projects/technology.jgit/releases/6.6.1"
            },
            {
              "url": "https://git.eclipse.org/c/jgit/jgit.git/commit/?id=9072103f3b3cf64dd12ad2949836ab98f62dabf1"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Improper handling of case insensitive filesystems in Eclipse JGit allows arbitrary file write",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eSetting git configuration option \u003ccode\u003ecore.symlinks = false\u003c/code\u003e\u0026nbsp;before checking out avoids the problem.\u003c/p\u003e"
                }
              ],
              "value": "Setting git configuration option core.symlinks = false\u00a0before checking out avoids the problem.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
        "assignerShortName": "eclipse",
        "cveId": "CVE-2023-4759",
        "datePublished": "2023-09-12T09:12:10.254Z",
        "dateReserved": "2023-09-04T16:06:00.689Z",
        "dateUpdated": "2024-08-02T07:37:59.574Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2014-9390 (GCVE-0-2014-9390)

    Vulnerability from cvelistv5 – Published: 2020-02-12 01:58 – Updated: 2024-08-06 13:40
    VLAI
    Summary
    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
    Severity
    No CVSS data available.
    CWE
    • n/a
    Date Public
    2014-12-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T13:40:25.038Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://news.ycombinator.com/item?id=8769667"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://article.gmane.org/gmane.linux.kernel/1853266"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://mercurial.selenic.com/wiki/WhatsNew"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://support.apple.com/kb/HT204147"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/blog/1938-git-client-vulnerability-announced"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1031404"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://libgit2.org/security/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2014-12-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-09-09T17:07:52.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://news.ycombinator.com/item?id=8769667"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://article.gmane.org/gmane.linux.kernel/1853266"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://mercurial.selenic.com/wiki/WhatsNew"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://support.apple.com/kb/HT204147"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/blog/1938-git-client-vulnerability-announced"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://securitytracker.com/id?1031404"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://libgit2.org/security/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2014-9390",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://news.ycombinator.com/item?id=8769667",
                  "refsource": "MISC",
                  "url": "https://news.ycombinator.com/item?id=8769667"
                },
                {
                  "name": "http://article.gmane.org/gmane.linux.kernel/1853266",
                  "refsource": "MISC",
                  "url": "http://article.gmane.org/gmane.linux.kernel/1853266"
                },
                {
                  "name": "http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html",
                  "refsource": "MISC",
                  "url": "http://git-blame.blogspot.com/2014/12/git-1856-195-205-214-and-221-and.html"
                },
                {
                  "name": "http://mercurial.selenic.com/wiki/WhatsNew",
                  "refsource": "MISC",
                  "url": "http://mercurial.selenic.com/wiki/WhatsNew"
                },
                {
                  "name": "http://support.apple.com/kb/HT204147",
                  "refsource": "MISC",
                  "url": "http://support.apple.com/kb/HT204147"
                },
                {
                  "name": "https://github.com/blog/1938-git-client-vulnerability-announced",
                  "refsource": "MISC",
                  "url": "https://github.com/blog/1938-git-client-vulnerability-announced"
                },
                {
                  "name": "http://securitytracker.com/id?1031404",
                  "refsource": "MISC",
                  "url": "http://securitytracker.com/id?1031404"
                },
                {
                  "name": "https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915",
                  "refsource": "MISC",
                  "url": "https://github.com/libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915"
                },
                {
                  "name": "https://libgit2.org/security/",
                  "refsource": "MISC",
                  "url": "https://libgit2.org/security/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2014-9390",
        "datePublished": "2020-02-12T01:58:27.000Z",
        "dateReserved": "2014-12-17T00:00:00.000Z",
        "dateUpdated": "2024-08-06T13:40:25.038Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }