VendorsEclipsejgitany version
Vulnerabilities

Eclipse JGit any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2014-9390
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
Published 2020-02-12 · Modified
9.8EPSS 0.756
CVE-2023-4759
Improper handling of case insensitive filesystems in Eclipse JGit allows arbitrary file write
Published 2023-09-12 · Modified
8.8EPSS 0.022
CVE-2025-4949
XXE vulnerability in Eclipse JGit
Published 2025-05-21 · Analyzed
6.8EPSS 0.008