CVE-2018-20433
published 2018-12-24CVE-2018-20433: c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.59%
90.6th percentile
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | c3p0 | < c3p0 0.9.1.2-10 (bookworm) | c3p0 0.9.1.2-10 (bookworm) |
| debian | debian_linux | — | — |
| mchange | c3p0 | — | — |
| mchange | c3p0 | >= 0 < 0.9.1.2-10 | 0.9.1.2-10 |
| mchange | c3p0 | >= 0 < 0.9.1.2-10 | 0.9.1.2-10 |
| mchange | c3p0 | >= 0 < 0.9.1.2-10 | 0.9.1.2-10 |
| mchange | c3p0 | >= 0 < 0.9.1.2-10 | 0.9.1.2-10 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
c3p0: XML external entity processing in extractXmlConfigFromInputStream
vendor_redhat·2018-12-20·CVSS 9.8
CVE-2018-20433 [CRITICAL] CWE-611 c3p0: XML external entity processing in extractXmlConfigFromInputStream
c3p0: XML external entity processing in extractXmlConfigFromInputStream
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
Statement: Red Hat Satellite 6 is not vulnerable to this issue, because the candlepin component who uses the c3p0 jar never passes a XML configuration file to c3p0, even though it includes a vulnerable version of the latter. Since this issue requires a XML files to be loaded by c3p0, an exploitation path doesn't exist.
Package: c3p0 (Red Hat BPM Suite 6) - Out of support scope
Package: c3p0 (Red Hat Decision Manager 7) - Not affected
Package: c3p0 (Red Hat Fuse 7) - Will not fix
Package: c3p0 (Red Hat JBoss BRMS 5) - Out of support scope
Package: c3p0 (Red Hat JBoss Data Grid 7) -
Debian
CVE-2018-20433: c3p0 - c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p...
vendor_debian·2018·CVSS 9.8
CVE-2018-20433 [CRITICAL] CVE-2018-20433: c3p0 - c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p...
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
Scope: local
bookworm: resolved (fixed in 0.9.1.2-10)
bullseye: resolved (fixed in 0.9.1.2-10)
forky: resolved (fixed in 0.9.1.2-10)
sid: resolved (fixed in 0.9.1.2-10)
trixie: resolved (fixed in 0.9.1.2-10)
GHSA
XML External Entity Reference in mchange:c3p0
ghsa·2019-01-07
CVE-2018-20433 [CRITICAL] CWE-611 XML External Entity Reference in mchange:c3p0
XML External Entity Reference in mchange:c3p0
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
OSV
XML External Entity Reference in mchange:c3p0
osv·2019-01-07
CVE-2018-20433 [CRITICAL] XML External Entity Reference in mchange:c3p0
XML External Entity Reference in mchange:c3p0
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
OSV
CVE-2018-20433: c3p0 0
osv·2018-12-24·CVSS 9.8
CVE-2018-20433 [CRITICAL] CVE-2018-20433: c3p0 0
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
No detection rules found.
No public exploits indexed.
HackerOne
c3p0 may be exploited by a Billion Laughs Attack when loading XML configuration
hackerone·2019-04-16·CVSS 6.2
[MEDIUM] c3p0 may be exploited by a Billion Laughs Attack when loading XML configuration
c3p0 may be exploited by a Billion Laughs Attack when loading XML configuration
> NOTE! Thanks for submitting a report! Please replace *all* the [square] sections below with the pertinent details. Remember, the more detail you provide, the easier it is for us to triage and respond quickly, so be sure to take your time filling out the report! Please refer to the **[example on our policy page](/central-security-project?view_policy=true#disclosure-example)**.
# Maven artifact
**groupId:** com.mchange
**artifactId:** c3p0
**version:** 0.9.5.3
# Vulnerability
## Vulnerability Description
> `c3p0/src/java/com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java` does not protect against recursive entity expansion when loading configuration.
## Additional Details
**Source File and Line Number:** https
Bugzilla
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream [epel-7]
bugzilla·2019-01-09·CVSS 9.8
CVE-2018-20433 [CRITICAL] CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream [epel-7]
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templat
Bugzilla
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream [fedora-all]
bugzilla·2019-01-09·CVSS 9.8
CVE-2018-20433 [CRITICAL] CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream [fedora-all]
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream
bugzilla·2019-01-09·CVSS 9.8
CVE-2018-20433 [CRITICAL] CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream
CVE-2018-20433 c3p0: XML external entity processing in extractXmlConfigFromInputStream
An XML external entity processing vulnerability was found in extractXmlConfigFromInputStream function in c3p0.
Upstream patch:
https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87b
Discussion:
Created c3p0 tracking bugs for this issue:
Affects: epel-7 [bug 1664731]
Affects: fedora-all [bug 1664730]
---
Statement:
Red Hat Satellite 6 is not vulnerable to this issue, because the candlepin component who uses the c3p0 jar never passes a XML configuration file to c3p0, even though it includes a vulnerable version of the latter. Since this issue requires a XML files to be loaded by c3p0, an exploitation path doesn't exist.
---
This vulnerability is out of security support
https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87bhttps://lists.debian.org/debian-lts-announce/2018/12/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQ47OFV57Y2DAHMGA5H3JOL4WHRWRFN4/https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87bhttps://lists.debian.org/debian-lts-announce/2018/12/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQ47OFV57Y2DAHMGA5H3JOL4WHRWRFN4/
2018-12-24
Published