CVE Database
/

CVE-2019-5427

Back to search

CVE-2019-5427

Published: Apr 22, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

VendorProductVersions

n/a

c3p0

affected
before 0.9.5.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now