CVE-2019-5427
Billion laughs attack in c3p0
Description
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Base CVSS
7.5
EPSS Score
4.14%
Introduced Version
0.9.2-pre2-RELEASE,0.9.5.3
Fix Available
0.9.5.4
Available Patches
Package
CVEs Fixed
Lines of Code Changed