Lucene search

K
cvelistHackeroneCVELIST:CVE-2019-5427
HistoryApr 22, 2019 - 8:52 p.m.

CVE-2019-5427

2019-04-2220:52:56
CWE-776
hackerone
www.cve.org
7

AI Score

7.3

Confidence

High

EPSS

0.023

Percentile

89.8%

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

CNA Affected

[
  {
    "product": "c3p0",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "before 0.9.5.4"
      }
    ]
  }
]