StackRadar

CVE-2025-4949

Medium

Advisory

Published 21 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
39
of 17,781 indexed, latest versions
Container images
37
deployed by those charts
Fix available
1 of 1
affected package

Eclipse JGit XML External Entity (XXE) Vulnerability

Carried by container images the latest versions of 39 of 17,781 indexed charts deploy, on 37 images.

Affected packageAffected versionsFixed inImages
org.eclipse.jgitmaven3.7.1.201504261725-r, 4.4.1.201607150455-r, 4.5.0.201609210915-r, 4.6.0.201612231935-r+22 more5.13.4.202507202350-r, 6.10.1.202505221210-r37
OSV records
GHSA-vrpq-qp53-qv56

Charts affected

39 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
org.eclipse.jgit@6.4.0.202211300538-r
6.10.1.202505221210-r

Open the chart page →

6,556
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
org.eclipse.jgit@5.13.0.202109080827-r
5.13.4.202507202350-r

Open the chart page →

7,713
sonarqube-ltssonarqubeVerified publisher1.0.16+981 of 4See more

sonarqube-lts sonarqube 1.0.16+98

1 of the 4 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
library/sonarqube:8.9.2-community88cd63154d4b
org.eclipse.jgit@5.9.0.202009080501-r
5.13.4.202507202350-r

Open the chart page →

4,099
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
org.eclipse.jgit@5.11.0.202103091610-r
5.13.4.202507202350-r
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
org.eclipse.jgit@5.11.0.202103091610-r
5.13.4.202507202350-r

Open the chart page →

8,698
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
org.eclipse.jgit@6.8.0.202311291450-r
6.10.1.202505221210-r

Open the chart page →

107,811
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.6.0f40a542832c4
org.eclipse.jgit@6.1.0.202203080745-r
6.10.1.202505221210-r

Open the chart page →

14,566
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
org.eclipse.jgit@5.13.2.202306221912-r
5.13.4.202507202350-r

Open the chart page →

5,398
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
org.eclipse.jgit@5.4.2.201908231537-r
5.13.4.202507202350-r

Open the chart page →

8,752
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
org.eclipse.jgit@5.8.1.202007141445-r
5.13.4.202507202350-r

Open the chart page →

6,531
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
org.eclipse.jgit@5.11.1.202105131744-r
5.13.4.202507202350-r

Open the chart page →

4,621
routrroutr0.0.101 of 2See more

routr routr 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
fonoster/routr:1.0.0-rc52ca65af17cbc
org.eclipse.jgit@4.4.1.201607150455-r
5.13.4.202507202350-r

Open the chart page →

4,983
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
org.eclipse.jgit@6.10.0.202406032230-r
6.10.1.202505221210-r

Open the chart page →

2,406
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
org.eclipse.jgit@5.13.0.202109080827-r
5.13.4.202507202350-r

Open the chart page →

7,713
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
org.eclipse.jgit@5.13.0.202109080827-r
5.13.4.202507202350-r

Open the chart page →

13,352
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
org.eclipse.jgit@5.1.3.201810200350-r
5.13.4.202507202350-r

Open the chart page →

9,144
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
org.eclipse.jgit@3.7.1.201504261725-r
5.13.4.202507202350-r

Open the chart page →

23,665
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
org.eclipse.jgit@5.13.2.202306221912-r
5.13.4.202507202350-r

Open the chart page →

5,398
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
org.eclipse.jgit@5.6.0.201912101111-r
5.13.4.202507202350-r

Open the chart page →

19,802
scorpio-brokerfiware0.3.31 of 10See more

scorpio-broker fiware 0.3.3

1 of the 10 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
org.eclipse.jgit@5.1.3.201810200350-r
5.13.4.202507202350-r

Open the chart page →

55,600
scorpiobrokerfiware0.1.21 of 10See more

scorpiobroker fiware 0.1.2

1 of the 10 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
org.eclipse.jgit@5.1.3.201810200350-r
5.13.4.202507202350-r

Open the chart page →

55,600
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
org.eclipse.jgit@6.3.0.202209071007-r
6.10.1.202505221210-r

Open the chart page →

14,312
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
org.eclipse.jgit@5.7.0.202003110725-r
5.13.4.202507202350-r

Open the chart page →

7,144
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
org.eclipse.jgit@4.5.0.201609210915-r
5.13.4.202507202350-r

Open the chart page →

19,295
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
org.eclipse.jgit@5.13.2.202306221912-r
5.13.4.202507202350-r

Open the chart page →

5,320
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
org.eclipse.jgit@5.9.0.202009080501-r
5.13.4.202507202350-r

Open the chart page →

2,273
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
org.eclipse.jgit@5.12.0.202106070339-r
5.13.4.202507202350-r

Open the chart page →

3,422
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
org.eclipse.jgit@6.10.0.202406032230-r
6.10.1.202505221210-r

Open the chart page →

5,826
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
org.eclipse.jgit@5.13.3.202401111512-r
5.13.4.202507202350-r

Open the chart page →

6,037
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
org.eclipse.jgit@5.12.0.202106070339-r
5.13.4.202507202350-r

Open the chart page →

13,607
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
org.eclipse.jgit@5.12.0.202106070339-r
5.13.4.202507202350-r

Open the chart page →

13,455
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
org.eclipse.jgit@6.10.0.202406032230-r
6.10.1.202505221210-r

Open the chart page →

4,203
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
org.eclipse.jgit@5.13.1.202206130422-r
5.13.4.202507202350-r

Open the chart page →

5,856
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
org.eclipse.jgit@4.6.0.201612231935-r
5.13.4.202507202350-r

Open the chart page →

11,841
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
org.eclipse.jgit@5.13.1.202206130422-r
5.13.4.202507202350-r

Open the chart page →

18,756
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
org.eclipse.jgit@6.1.0.202203080745-r
6.10.1.202505221210-r

Open the chart page →

25,394
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
org.eclipse.jgit@6.6.1.202309021850-r
6.10.1.202505221210-r

Open the chart page →

2,144
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
org.eclipse.jgit@5.3.0.201903130848-r
5.13.4.202507202350-r

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
org.eclipse.jgit@5.10.0.202012080955-r
5.13.4.202507202350-r

Open the chart page →

28,605
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2025-4949.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
org.eclipse.jgit@5.0.0.201805301535-rc2
5.13.4.202507202350-r

Open the chart page →

6,213

Container images carrying it

37 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/nifi-registry:1.26.07cdfd8deec92
org.eclipse.jgit@5.13.2.202306221912-r
5.13.4.202507202350-r
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
org.eclipse.jgit@5.1.3.201810200350-r
5.13.4.202507202350-r
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
org.eclipse.jgit@5.13.0.202109080827-r
5.13.4.202507202350-r
2
1dev/server:11.9.0cd5b12fe5471
org.eclipse.jgit@5.13.3.202401111512-r
5.13.4.202507202350-r
1
2martens/configserver:latestbf1cdb80239d
org.eclipse.jgit@6.6.1.202309021850-r
6.10.1.202505221210-r
1
apache/nifi-registry:1.14.0090b7f87ec7f
org.eclipse.jgit@5.11.1.202105131744-r
5.13.4.202507202350-r
1
apache/nifi-registry:1.27.063b8e3e40742
org.eclipse.jgit@5.13.2.202306221912-r
5.13.4.202507202350-r
1
apache/nifi-registry:0.8.0974efa2f21da
org.eclipse.jgit@5.8.1.202007141445-r
5.13.4.202507202350-r
1
assistiot/identity-manager_kc:latest0df4b4fa899a
org.eclipse.jgit@5.13.0.202109080827-r
5.13.4.202507202350-r
1
fonoster/routr:1.0.0-rc52ca65af17cbc
org.eclipse.jgit@4.4.1.201607150455-r
5.13.4.202507202350-r
1
gocd/gocd-server:v19.3.02da45cb09d57
org.eclipse.jgit@5.1.3.201810200350-r
5.13.4.202507202350-r
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
org.eclipse.jgit@6.3.0.202209071007-r
6.10.1.202505221210-r
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
org.eclipse.jgit@5.12.0.202106070339-r
5.13.4.202507202350-r
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
org.eclipse.jgit@5.12.0.202106070339-r
5.13.4.202507202350-r
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
org.eclipse.jgit@4.5.0.201609210915-r
5.13.4.202507202350-r
1
jhipster/jhipster-registry:latest7184525acd4d
org.eclipse.jgit@5.13.1.202206130422-r
5.13.4.202507202350-r
1
keyfactor/signserver-ce:7.3.2798fbbe00283
org.eclipse.jgit@6.10.0.202406032230-r
6.10.1.202505221210-r
1
library/sonarqube:10.7.0-community0842dcd4c8f8
org.eclipse.jgit@6.10.0.202406032230-r
6.10.1.202505221210-r
1
library/sonarqube:6.7.6-community0ae5169e3d0f
org.eclipse.jgit@4.6.0.201612231935-r
5.13.4.202507202350-r
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
org.eclipse.jgit@5.11.0.202103091610-r
5.13.4.202507202350-r
1
library/sonarqube:8.9.2-community88cd63154d4b
org.eclipse.jgit@5.9.0.202009080501-r
5.13.4.202507202350-r
1
library/sonarqube:8.2-communitya246bc64207e
org.eclipse.jgit@5.3.0.201903130848-r
5.13.4.202507202350-r
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
org.eclipse.jgit@5.11.0.202103091610-r
5.13.4.202507202350-r
1
library/sonarqube:8.9-communityeb2f0be32efd
org.eclipse.jgit@5.9.0.202009080501-r
5.13.4.202507202350-r
1
library/sonarqube:10.0.0-communityef9723cf4fe4
org.eclipse.jgit@6.4.0.202211300538-r
6.10.1.202505221210-r
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
org.eclipse.jgit@5.0.0.201805301535-rc2
5.13.4.202507202350-r
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
org.eclipse.jgit@6.10.0.202406032230-r
6.10.1.202505221210-r
1
rundeck/rundeck:3.2.74d64fe56f767
org.eclipse.jgit@5.6.0.201912101111-r
5.13.4.202507202350-r
1
rundeck/rundeck:3.0.16b13e8059ad72
org.eclipse.jgit@3.7.1.201504261725-r
5.13.4.202507202350-r
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
org.eclipse.jgit@5.13.1.202206130422-r
5.13.4.202507202350-r
1
thingsboard/tb-node:3.4.1645f43b688f7
org.eclipse.jgit@6.1.0.202203080745-r
6.10.1.202505221210-r
1
thingsboard/tb-node:3.6.0f40a542832c4
org.eclipse.jgit@6.1.0.202203080745-r
6.10.1.202505221210-r
1
vlebediantsev/config-server-another:lateste7f20450d2ae
org.eclipse.jgit@5.12.0.202106070339-r
5.13.4.202507202350-r
1
wistefan/mvf:lateste0887302b2d8
org.eclipse.jgit@5.7.0.202003110725-r
5.13.4.202507202350-r
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
org.eclipse.jgit@5.4.2.201908231537-r
5.13.4.202507202350-r
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
org.eclipse.jgit@5.10.0.202012080955-r
5.13.4.202507202350-r
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
org.eclipse.jgit@6.8.0.202311291450-r
6.10.1.202505221210-r
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.