Description
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1621-1 | c3p0 security update |
EUVD |
EUVD-2019-0193 | c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization. |
Github GHSA |
GHSA-q485-j897-qc27 | XML External Entity Reference in mchange:c3p0 |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:58:19.055Z
Reserved: 2018-12-24T00:00:00.000Z
Link: CVE-2018-20433
No data.
Status : Modified
Published: 2018-12-24T13:29:00.210
Modified: 2024-11-21T04:01:28.417
Link: CVE-2018-20433
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA