Actions
Bug #27006
openUpdate jgit to last version against XXE
Status:
Pending release
Priority:
N/A
Assignee:
Category:
Security
Target version:
Pull Request:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No
Description
JGit used in futur Rudder 9.0 has an XXE: https://github.com/Normation/rudder/security/dependabot/179
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4949
We aren't effected since we don't parse external repo or S3 bucket in our use case.
Updated by François ARMAND 8 days ago
- Status changed from In progress to Pending technical review
- Assignee changed from François ARMAND to Clark ANDRIANASOLO
- Pull Request set to https://github.com/Normation/rudder/pull/6411
Updated by Anonymous 8 days ago
- Status changed from Pending technical review to Pending release
Applied in changeset rudder|067ce41b933ac74971af779c0714a2950e33ac98.
Actions