Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20736
HistoryJul 08, 2019 - 3:36 p.m.

XML Entity Expansion (XEE)

2019-07-0815:36:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.023

Percentile

89.8%

c3p0 is vulnerable to XML entity expansion (XEE). Missing protections against recursive entity expansion when loading configuration allows remote attackers to exploit the billion laughs attack by loading malicious XML configurations.