c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Project Subscriptions

Vendors Products
Fedoraproject Subscribe
Mchange Subscribe
Communications Ip Service Activator Subscribe
Communications Session Route Manager Subscribe
Documaker Subscribe
Enterprise Manager Base Platform Subscribe
Enterprise Manager Ops Center Subscribe
Flexcube Private Banking Subscribe
Hyperion Infrastructure Technology Subscribe
Retail Xstore Point Of Service Subscribe
Webcenter Sites Subscribe
Jboss Fuse Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0409 c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Github GHSA Github GHSA GHSA-84p2-vf58-xhxv Billion laughs attack in c3p0
Ubuntu USN Ubuntu USN USN-5293-1 c3p0 vulnerability
Ubuntu USN Ubuntu USN USN-5293-2 c3p0 vulnerability
Ubuntu USN Ubuntu USN USN-7571-1 c3p0 vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-04T19:54:53.546Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-04-22T21:29:00.523

Modified: 2025-09-05T17:23:58.510

Link: CVE-2019-5427

cve-icon Redhat

Severity : Low

Publid Date: 2019-04-17T00:00:00Z

Links: CVE-2019-5427 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses