Fixed
Details
Assignee
Benjamin ReedBenjamin ReedReporter
Will KeaneyWill KeaneyComponents
Sprint
NoneAffects versions
Priority
Major
Details
Details
Assignee
Benjamin Reed
Benjamin ReedReporter
Will Keaney
Will KeaneyComponents
Sprint
None
Affects versions
Priority
PagerDuty
PagerDuty
PagerDuty
Created May 10, 2019 at 2:46 PM
Updated May 23, 2019 at 8:11 PM
Resolved May 14, 2019 at 2:29 PM
From GitHub's vulnerability scanner:
CVE-2018-20433 More information
moderate severity
Vulnerable versions: <= 0.9.5.2
Patched version: 0.9.5.3
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.