Skip to content
This repository has been archived by the owner on Dec 12, 2019. It is now read-only.

CAM-7974 XXE protection for different parser implementations #3

Merged

Conversation

robo-w
Copy link

@robo-w robo-w commented Jun 28, 2017

As an addition to the previous pull request, the AbstractModelParser also sets features, that disallow doctypes and external entities.

It was manually tested, that BPMN files generated by the camunda modeler are parsed correctly with these settings.

See https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Prevention_Cheat_Sheet for details

@roboticbird
Copy link
Contributor

fix(XML-model): XXE vulnerability of xml parser fix

related to CAM-7974

@roboticbird roboticbird merged commit cda3c86 into camunda:master Jun 28, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
2 participants