-
Bug
-
Resolution: Done
-
Critical
-
None
-
None
-
Medium
For description, see RESTEASY-637. I fixed the problem for org.w3c.dom.Document inputs, but not for JAXB XML inputs.
This is a clone of RESTEASY-647 for fix version 3.0-alpha-1.
Since RESTEasy 3 is a major release, we can change the default to the safer behavior of not expanding external entities.
- is cloned by
-
RESTEASY-647 RestEasy and XXE injection - Services that accept XML are vulnerable to XXE attacks, Part II
- Closed