VDB

CVE-2018-20433

CVE-2018-20433 PUBLISHED

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

EPSS 2.40% · 85.4th percentile

Risk Scores

EPSS Score
2.40%
85.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSc3p00.9.1.2-7, 0.9.1.2-9, 0
Ubuntu:16.04:LTSc3p00.9.1.2-9, 0
Ubuntu:18.04:LTSc3p00.9.1.2-9, 0

Timeline

  • CVE Published
  • Apr 16, 2019 PoC Published
  • Apr 14, 2021 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 20, 2025 EPSS Score
  • Mar 22, 2025 EPSS Score
  • Mar 24, 2025 EPSS Score
  • Mar 25, 2025 EPSS Score
  • Mar 28, 2025 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Apr 4, 2025 EPSS Score
  • Apr 6, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›