CVE-2019-5427

Related Vulnerabilities: CVE-2019-5427  

Impact: Moderate Public Date: 2019-04-17 CWE: CWE-776 Bugzilla: 1709860: CVE-2019-5427 c3p0: loading XML configuration leads to denial of service c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

The MITRE CVE dictionary describes this issue as:

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Find out more about CVE-2019-5427 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Satellite 6 c3p0 Under investigation
Red Hat Satellite 5 c3p0 Under investigation
Red Hat OpenShift Application Runtimes 1.0 vertx Under investigation
Red Hat Mobile Application Platform On-Premise 4 c3p0 Under investigation
Red Hat JBoss Fuse 7 c3p0 Under investigation
Red Hat JBoss Fuse 6 c3p0 Under investigation
Red Hat JBoss Enterprise SOA Platform 5 c3p0 Under investigation
Red Hat JBoss EWS 2 c3p0 Under investigation
Red Hat JBoss BPMS 6 c3p0 Under investigation
Red Hat Gluster Storage 3 c3p0 Under investigation