CVE-2018-20433XML External Entity (XXE) Injection in C3p0

Severity
9.8CRITICALNVD
EPSS
2.4%
top 14.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Latest updateJan 9

Description

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

Debianmchange/c3p0< 0.9.1.2-10+3
NVDmchange/c3p00.9.5.2

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

4
GHSA
XML External Entity Reference in mchange:c3p02019-01-07
OSV
XML External Entity Reference in mchange:c3p02019-01-07
OSV
CVE-2018-20433: c3p0 02018-12-24
CVEList
CVE-2018-20433: c3p0 02018-12-24

📋Vendor Advisories

2
Red Hat
c3p0: XML external entity processing in extractXmlConfigFromInputStream2018-12-20
Debian
CVE-2018-20433: c3p0 - c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p...2018

💬Community

3
Bugzilla
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream [epel-7]2019-01-09
Bugzilla
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream [fedora-all]2019-01-09
Bugzilla
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream2019-01-09
CVE-2018-20433 — XML External Entity (XXE) Injection | cvebase