GHSA-q485-j897-qc27
Dashboard / Vulnerabilities / GHSA-q485-j897-qc27
Summary: XML External Entity Reference in mchange:c3p0
Details: c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-20433, https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87b, https://github.com/advisories/GHSA-q485-j897-qc27, https://github.com/zhutougg/c3p0, https://lists.debian.org/debian-lts-announce/2018/12/msg00021.html, https://lists.fedoraproject.org/archives/list/[email protected]/message/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR, https://lists.fedoraproject.org/archives/list/[email protected]/message/MQ47OFV57Y2DAHMGA5H3JOL4WHRWRFN4
Affected packages
Package
Name: com.mchange:c3p0
Purl: pkg:maven/com.mchange/c3p0
Affected ranges
Type: ECOSYSTEM
Events:
