-
Bug
-
Resolution: Done
-
Major
-
26.0.1.Final
-
None
Currently some codepoints use a native javax.xml.parsers.DocumentBuilderFactory or javax.xml.stream.XMLInputFactory. Restriction of XML External Entity Reference is lacking.
- org/jboss/as/jdr/util/XMLSanitizer
Fix:
Use o.w.c.xml.*Factories
Related to: