c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
[
{
"signature_type": "Function",
"digest": {
"function_hash": "285633924274454538166616215983368224587",
"length": 184.0
},
"target": {
"file": "src/java/com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java",
"function": "extractXmlConfigFromInputStream"
},
"signature_version": "v1",
"id": "CVE-2018-20433-5da07470",
"deprecated": false,
"source": "https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87b"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"189690253779608637118636279419339185924",
"203546079303241071003653587684751722518",
"82634546918609591678268069562506055393",
"1203531496525078502927178182878650541"
]
},
"target": {
"file": "src/java/com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java"
},
"signature_version": "v1",
"id": "CVE-2018-20433-7052ecb0",
"deprecated": false,
"source": "https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87b"
}
]