Skip to content

reject doctype declarations in XomDriver#464

Open
jmestwa-coder wants to merge 1 commit into
x-stream:masterfrom
jmestwa-coder:xomdriver-disallow-doctype
Open

reject doctype declarations in XomDriver#464
jmestwa-coder wants to merge 1 commit into
x-stream:masterfrom
jmestwa-coder:xomdriver-disallow-doctype

Conversation

@jmestwa-coder
Copy link
Copy Markdown

XomDriver builds documents with a bare nu.xom.Builder, which resolves external general and parameter entities by default, leaving fromXML on untrusted XML open to XXE. Build the Builder from an XMLReader with disallow-doctype-decl set, matching DomDriver and the other drivers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant