Actions
Bug #27006
closedUpdate jgit to last version against XXE
Pull Request:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No
Description
JGit used in futur Rudder 9.0 has an XXE: https://github.com/Normation/rudder/security/dependabot/179
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4949
We aren't effected since we don't parse external repo or S3 bucket in our use case.
Actions