QID 980290

QID 980290: Java (maven) Security Update for com.mchange:c3p0 (GHSA-84p2-vf58-xhxv)

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-84p2-vf58-xhxv for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980290

    Software Advisories
    Advisory ID Software Component Link
    GHSA-84p2-vf58-xhxv com.mchange:c3p0 URL Logo github.com/advisories/GHSA-84p2-vf58-xhxv