Project

General

Profile

Actions

Bug #27006

closed

Update jgit to last version against XXE

Added by François ARMAND 3 months ago. Updated 23 days ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

JGit used in futur Rudder 9.0 has an XXE: https://github.com/Normation/rudder/security/dependabot/179

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4949

We aren't effected since we don't parse external repo or S3 bucket in our use case.


Subtasks 1 (0 open1 closed)

Bug #27011: JGit vulnerability (XXE)ReleasedClark ANDRIANASOLOActions
Actions

Also available in: Atom PDF