CVE-2019-5427: High severity mchange c3p0 vulnerability
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/c3p0to a version that resolves this vulnerability.Fixed in 0.9.5.4 - Upgrade
Upgrade
c3p0to a version that resolves this vulnerability.Fixed in 0.9.5.4
Event History
Frequently Asked Questions
What is CVE-2019-5427?
CVE-2019-5427 refers to a vulnerability in c3p0 version < 0.9.5.4 that can be exploited by a billion laughs attack when loading XML configuration.
How severe is CVE-2019-5427?
CVE-2019-5427 has a severity value of 7.5, which is considered high.
Which software versions are affected by CVE-2019-5427?
c3p0 versions prior to 0.9.5.4 are affected by CVE-2019-5427.
What is the remedy for CVE-2019-5427?
To fix CVE-2019-5427, update c3p0 to version 0.9.5.4 or later.
Where can I find more information about CVE-2019-5427?
More information about CVE-2019-5427 can be found at the following references: 1. HackerOne report: https://hackerone.com/reports/509315 2. CVE Details: http://www.cvedetails.com/cve/CVE-2019-5427/ 3. GitHub commit: https://github.com/swaldman/c3p0/commit/f38f27635c384806c2a9d6500d80183d9f09d78b