Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20433

Опубликовано: 20 дек. 2018
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

Отчет

Red Hat Satellite 6 is not vulnerable to this issue, because the candlepin component who uses the c3p0 jar never passes a XML configuration file to c3p0, even though it includes a vulnerable version of the latter. Since this issue requires a XML files to be loaded by c3p0, an exploitation path doesn't exist.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6c3p0Out of support scope
Red Hat Decision Manager 7c3p0Not affected
Red Hat Fuse 7c3p0Will not fix
Red Hat JBoss BRMS 5c3p0Out of support scope
Red Hat JBoss Data Grid 7c3p0Not affected
Red Hat JBoss Data Virtualization 6c3p0Out of support scope
Red Hat JBoss Enterprise Application Platform 5c3p0Out of support scope
Red Hat JBoss Enterprise Web Server 2c3p0Out of support scope
Red Hat JBoss Fuse 6c3p0Out of support scope
Red Hat JBoss SOA Platform 5c3p0Out of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1664729c3p0: XML external entity processing in extractXmlConfigFromInputStream

EPSS

Процентиль: 85%
0.02404
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

CVSS3: 9.8
nvd
около 7 лет назад

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

CVSS3: 9.8
debian
около 7 лет назад

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mcha ...

CVSS3: 9.8
github
около 7 лет назад

XML External Entity Reference in mchange:c3p0

EPSS

Процентиль: 85%
0.02404
Низкий

7.3 High

CVSS3