Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-5427

Опубликовано: 17 апр. 2019
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Отчет

Red Hat Satellite 6 is not vulnerable to this issue, because the candlepin component who uses the c3p0 jar never passes a XML configuration file to c3p0, even though it includes a vulnerable version of the latter. Since this issue requires a XML files to be loaded by c3p0, an exploitation path doesn't exist.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6c3p0Out of support scope
Red Hat JBoss Enterprise Web Server 2c3p0Out of support scope
Red Hat JBoss Fuse 6c3p0Out of support scope
Red Hat JBoss SOA Platform 5c3p0Out of support scope
Red Hat Mobile Application Platform 4c3p0Out of support scope
Red Hat OpenShift Application Runtimesc3p0Fix deferred
Red Hat Process Automation 7c3p0Not affected
Red Hat Satellite 5c3p0Out of support scope
Red Hat Satellite 6candlepinNot affected
Red Hat Storage 3c3p0Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=1709860c3p0: loading XML configuration leads to denial of service

EPSS

Процентиль: 88%
0.0406
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

CVSS3: 7.5
nvd
почти 7 лет назад

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

CVSS3: 7.5
debian
почти 7 лет назад

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack whe ...

CVSS3: 7.5
github
почти 7 лет назад

Billion laughs attack in c3p0

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость функции ConfigXmlUtils библиотеки работы с JDBC-драйверами c3p0, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 88%
0.0406
Низкий

4.4 Medium

CVSS3