Skip to content

Enable secure processing on all DocumentBuilderFactory.newInstance()#321

Merged
asfgit merged 1 commit into
apache:masterfrom
coheigea:dbf_secureproc
Nov 22, 2018
Merged

Enable secure processing on all DocumentBuilderFactory.newInstance()#321
asfgit merged 1 commit into
apache:masterfrom
coheigea:dbf_secureproc

Conversation

@coheigea
Copy link
Copy Markdown
Contributor

Good security practices say that all DocumentBuilderFactory instances should enable the secure processing feature and disable doctypes to avoid XXE attacks.

@jbonofre
Copy link
Copy Markdown
Member

R: @jbonofre

@jbonofre
Copy link
Copy Markdown
Member

LGTM, I will merged when Jenkins is happy.

@asfgit asfgit merged commit a87b61e into apache:master Nov 22, 2018
asfgit pushed a commit that referenced this pull request Nov 22, 2018
@gtully
Copy link
Copy Markdown
Contributor

gtully commented Nov 22, 2018

it would be nice if there was a corresponding jira to track this improvement into a release.

@coheigea coheigea deleted the dbf_secureproc branch November 22, 2018 14:49
@coheigea
Copy link
Copy Markdown
Contributor Author

Hi Gary! Here it is: https://issues.apache.org/jira/browse/AMQ-7110

@gtully
Copy link
Copy Markdown
Contributor

gtully commented Nov 22, 2018

thanks Colm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants