Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-16198

Restriction of XML External Entity Reference (XXE)

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 26.1.0.Final, 27.0.0.Alpha1
    • 26.0.1.Final
    • JDR
    • None

    Description

      Currently some codepoints use a native javax.xml.parsers.DocumentBuilderFactory or javax.xml.stream.XMLInputFactory. Restriction of XML External Entity Reference is lacking.

      • org/jboss/as/jdr/util/XMLSanitizer

      Fix:
      Use o.w.c.xml.*Factories

      Related to:

      Attachments

        Activity

          People

            xf01213 Boris Unckel (Inactive)
            xf01213 Boris Unckel (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: