Please update c3p0 to 0.9.5.4+ to pick up a CVE fix that was fixed in 0.9.5.4:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5427