Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-16198

Restriction of XML External Entity Reference (XXE)

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 26.1.0.Final, 27.0.0.Alpha1
    • 26.0.1.Final
    • JDR
    • None

      Currently some codepoints use a native javax.xml.parsers.DocumentBuilderFactory or javax.xml.stream.XMLInputFactory. Restriction of XML External Entity Reference is lacking.

      • org/jboss/as/jdr/util/XMLSanitizer

      Fix:
      Use o.w.c.xml.*Factories

      Related to:

              xf01213 Boris Unckel (Inactive)
              xf01213 Boris Unckel (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: