CVE-2018-20433
XML External Entity Reference in mchange:c3p0
Description
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
Base CVSS
9.8
EPSS Score
2.4%
Introduced Version
0.9.2-pre2-RELEASE
Fix Available
0.9.5.3
Available Patches
Package
CVEs Fixed
Lines of Code Changed