GHSA-84p2-vf58-xhxv
Dashboard / Vulnerabilities / GHSA-84p2-vf58-xhxv
Summary: Billion laughs attack in c3p0
Details: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-5427, https://hackerone.com/reports/509315, https://lists.fedoraproject.org/archives/list/[email protected]/message/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR, https://lists.fedoraproject.org/archives/list/[email protected]/message/MQ47OFV57Y2DAHMGA5H3JOL4WHRWRFN4, https://www.oracle.com/security-alerts/cpuapr2020.html, https://www.oracle.com/security-alerts/cpujan2021.html, https://www.oracle.com/security-alerts/cpujul2020.html, https://www.oracle.com/security-alerts/cpuoct2020.html, https://www.oracle.com/security-alerts/cpuoct2021.html
Affected packages
Package
Name: com.mchange:c3p0
Purl: pkg:maven/com.mchange/c3p0
Affected ranges
Type: ECOSYSTEM
Events:
