c3p0: loading XML configuration leads to denial of service
Published Apr 22, 2019
7.5
HIGHCVSS 3.1
EPSS 4.88%
Description
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Affected products
- Vendor n/a Product C3p0 Defaultn/a
- Version before 0.9.5.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | C3p0 | n/a |
|
Configuration 2
- 29
- 30
Configuration 3
- 7.3.0
- 7.4.0
- ≥ 8.2.0 · ≤ 8.2.2
- ≥ 12.6.0 · ≤ 12.6.6
- 13.2.1.0
- 12.4.0.0
- 12.0.0
- 12.1.0
- 11.1.2.4
- 15.0
- 16.0
- 17.0
- 18.0
- 19.0
- 12.2.1.3.0
- 12.2.1.4.0
No data.
Red Hat Fuse 7.6.0
c3p0
Fixed · RHSA-2020:0983
Red Hat BPM Suite 6
c3p0
Out of support scope
Red Hat JBoss Enterprise Web Server 2
c3p0
Out of support scope
Red Hat JBoss Fuse 6
c3p0
Out of support scope
Red Hat JBoss SOA Platform 5
c3p0
Out of support scope
Red Hat Mobile Application Platform 4
c3p0
Out of support scope
Red Hat OpenShift Application Runtimes
c3p0
Fix deferred
Red Hat Process Automation 7
c3p0
Not affected
Red Hat Satellite 5
c3p0
Out of support scope
Red Hat Satellite 6
candlepin
Not affected
Red Hat Storage 3
c3p0
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.6.0 | c3p0 | Fixed | RHSA-2020:0983 |
| Red Hat BPM Suite 6 | c3p0 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Web Server 2 | c3p0 | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | c3p0 | Out of support scope | n/a |
| Red Hat JBoss SOA Platform 5 | c3p0 | Out of support scope | n/a |
| Red Hat Mobile Application Platform 4 | c3p0 | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | c3p0 | Fix deferred | n/a |
| Red Hat Process Automation 7 | c3p0 | Not affected | n/a |
| Red Hat Satellite 5 | c3p0 | Out of support scope | n/a |
| Red Hat Satellite 6 | candlepin | Not affected | n/a |
| Red Hat Storage 3 | c3p0 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Satellite 6 is not vulnerable to this issue, because the candlepin component who uses the c3p0 jar never passes a XML configuration file to c3p0, even though it includes a vulnerable version of the latter. Since this issue requires a XML files to be loaded by c3p0, an exploitation path doesn't exist.
References (15)
- https://access.redhat.com/security/cve/CVE-2019-5427 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1709860 Issue Tracking
- https://github.com/advisories/GHSA-84p2-vf58-xhxv Advisory
- https://hackerone.com/reports/509315 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR/ vendor-advisoryx_refsource_FEDORAThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQ47OFV57Y2DAHMGA5H3JOL4WHRWRFN4/ vendor-advisoryx_refsource_FEDORAThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQ47OFV57Y2DAHMGA5H3JOL4WHRWRFN4/
- https://nvd.nist.gov/vuln/detail/CVE-2019-5427
- https://www.cve.org/CVERecord?id=CVE-2019-5427
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.