CVE-2019-5427

Source
https://cve.org/CVERecord?id=CVE-2019-5427
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5427.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-5427
Aliases
Downstream
Related
Published
2019-04-22T21:29:00.523Z
Modified
2026-02-13T01:46:01.954643Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

References

Affected packages

Git / github.com/zhutougg/c3p0

Affected ranges

Type
GIT
Repo
https://github.com/zhutougg/c3p0
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

c3p0-0.*
c3p0-0.8.4
c3p0-0.8.4-test1
c3p0-0.8.4-test2
c3p0-0.8.4-test5
c3p0-0.8.4.1
c3p0-0.8.4.2
c3p0-0.8.4.5
c3p0-0.8.5
c3p0-0.8.5-pre2
c3p0-0.8.5-pre4
c3p0-0.8.5-pre7
c3p0-0.8.5-pre8
c3p0-0.8.5-pre9
c3p0-0.8.5.1
c3p0-0.8.5.2
c3p0-0.9.0
c3p0-0.9.0-pre2
c3p0-0.9.0-pre3
c3p0-0.9.0-pre4
c3p0-0.9.0-pre5
c3p0-0.9.0-pre6
c3p0-0.9.0.2
c3p0-0.9.0.3
c3p0-0.9.0.4
c3p0-0.9.1
c3p0-0.9.1-pre10
c3p0-0.9.1-pre11
c3p0-0.9.1-pre12
c3p0-0.9.1-pre5
c3p0-0.9.1-pre5a
c3p0-0.9.1-pre6
c3p0-0.9.1-pre7
c3p0-0.9.1-pre9
c3p0-0.9.1.1
c3p0-0.9.1.2
c3p0-0.9.2
c3p0-0.9.2-pre1
c3p0-0.9.2-pre2
c3p0-0.9.2-pre2-RELEASE
c3p0-0.9.2-pre3
c3p0-0.9.2-pre4
c3p0-0.9.2-pre5
c3p0-0.9.2-pre6
c3p0-0.9.2-pre7
c3p0-0.9.2-pre8
c3p0-0.9.5-pre1
c3p0-0.9.5-pre2
c3p0-0.9.5-pre3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5427.json"