CVE-2019-5427: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
(updated )
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
References
Detect and mitigate CVE-2019-5427 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →