Uploaded image for project: 'ZooKeeper'
  1. ZooKeeper
  2. ZOOKEEPER-3235

Enable secure processing and disallow DTDs in the SAXParserFactory

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 3.5.4, 3.6.0, 3.4.13
    • 3.6.0, 3.5.5
    • jute
    • None

    Description

      We should enable the secure processing feature and disallow DTDs in the SAXParserFactory. This prevents a number of possible XXE style attacks.

      Attachments

        Issue Links

          Activity

            People

              coheigea Colm O hEigeartaigh
              coheigea Colm O hEigeartaigh
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: