Skip to content

Set disableSecurityProcessing to false by default instead of true to prevent XXE attacks#1867

Open
beth-soptim wants to merge 1 commit intoeclipse-ee4j:masterfrom
beth-soptim:disableSecurityProcessingFalse
Open

Set disableSecurityProcessing to false by default instead of true to prevent XXE attacks#1867
beth-soptim wants to merge 1 commit intoeclipse-ee4j:masterfrom
beth-soptim:disableSecurityProcessingFalse

Conversation

@beth-soptim
Copy link

jaxb-ri should use a secure config by default to prevent to be vulnerable to XXE attacks.

I guess this is not the case until now for compability reasons?

A release note should probably be added.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments