Описание
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 0.9.1.2-9+deb8u1ubuntu0.18.04.1 |
| cosmic | ignored | end of life |
| devel | released | 0.9.1.2-10ubuntu1 |
| disco | ignored | end of life |
| eoan | ignored | end of life |
| esm-apps/bionic | released | 0.9.1.2-9+deb8u1ubuntu0.18.04.1 |
| esm-apps/focal | released | 0.9.1.2-10ubuntu0.20.04.1 |
| esm-apps/jammy | released | 0.9.1.2-10ubuntu1 |
| esm-apps/noble | released | 0.9.1.2-10ubuntu1 |
| esm-apps/xenial | released | 0.9.1.2-9+deb8u1ubuntu0.16.04.1~esm1 |
Показывать по
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack whe ...
Уязвимость функции ConfigXmlUtils библиотеки работы с JDBC-драйверами c3p0, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5 Medium
CVSS2
7.5 High
CVSS3