Lucene search

K
osvGoogleOSV:GHSA-84P2-VF58-XHXV
HistoryApr 23, 2019 - 4:03 p.m.

Billion laughs attack in c3p0

2019-04-2316:03:18
Google
osv.dev
19

EPSS

0.023

Percentile

89.8%

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.