Back to search
CVE-2019-5427
Published: Apr 22, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
| Vendor | Product | Versions |
|---|---|---|
n/a | c3p0 | affected before 0.9.5.4 |
Weaknesses (CWE)
References
FEDORA-2019-cb14e234fc
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-063672154a
vendor-advisory
x_refsource_FEDORA
https://www.oracle.com/security-alerts/cpuapr2020.html
x_refsource_MISC
https://www.oracle.com/security-alerts/cpujul2020.html
x_refsource_MISC
https://hackerone.com/reports/509315
x_refsource_MISC
https://www.oracle.com/security-alerts/cpuoct2020.html
x_refsource_MISC
https://www.oracle.com/security-alerts/cpujan2021.html
x_refsource_MISC
https://www.oracle.com/security-alerts/cpuoct2021.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now