Bugzilla – Bug 1120648
VUL-1: CVE-2018-20433: c3p0: XXE in extractXmlConfigFromInputStream
Last modified: 2022-04-06 10:25:15 UTC
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20433 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-20433.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20433 https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87b
Fixed with https://build.opensuse.org/request/show/886654