diff --git a/advisories/github-reviewed/2025/05/GHSA-vrpq-qp53-qv56/GHSA-vrpq-qp53-qv56.json b/advisories/github-reviewed/2025/05/GHSA-vrpq-qp53-qv56/GHSA-vrpq-qp53-qv56.json index 0ae1fa05d7173..5c063b6240735 100644 --- a/advisories/github-reviewed/2025/05/GHSA-vrpq-qp53-qv56/GHSA-vrpq-qp53-qv56.json +++ b/advisories/github-reviewed/2025/05/GHSA-vrpq-qp53-qv56/GHSA-vrpq-qp53-qv56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vrpq-qp53-qv56", - "modified": "2025-11-27T09:12:49Z", + "modified": "2025-11-27T09:13:29Z", "published": "2025-05-21T21:31:37Z", "aliases": [ "CVE-2025-4949" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green" + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N" } ], "affected": [ @@ -101,7 +101,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "5.13.5.202508271544-r" + "introduced": "6.0.0.202110060947-m1" }, { "fixed": "6.0.0.202111291000-r" @@ -123,11 +123,14 @@ "introduced": "0" }, { - "fixed": "5.13.4.202507202350-r" + "fixed": "5.13.4.202507202350-r, 5.13.5.202508271544-r" } ] } - ] + ], + "database_specific": { + "last_known_affected_version_range": "< 5.13.4.202507202350-r" + } } ], "references": [ @@ -151,6 +154,10 @@ "type": "WEB", "url": "https://projects.eclipse.org/projects/technology.jgit/releases/5.13.4" }, + { + "type": "WEB", + "url": "https://projects.eclipse.org/projects/technology.jgit/releases/5.13.5" + }, { "type": "WEB", "url": "https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1"