Document XML parser usage against security false positives
Prior to this commit, our XML parser usage would be already haredened against XXE (XML External Entities) attacks. Still, we recently received several invalid security reports claiming that our setup should be hardened. This commit documents a few usages of XML parsers to add some more context and hopefully prevent future invalid reports. Closes gh-33713
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2018 the original author or authors.
|
||||
* Copyright 2002-2024 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -88,6 +88,9 @@ public class DefaultDocumentLoader implements DocumentLoader {
|
||||
protected DocumentBuilderFactory createDocumentBuilderFactory(int validationMode, boolean namespaceAware)
|
||||
throws ParserConfigurationException {
|
||||
|
||||
// This document loader is used for loading application configuration files.
|
||||
// As a result, attackers would need complete write access to application configuration
|
||||
// to leverage XXE attacks. This does not qualify as privilege escalation.
|
||||
DocumentBuilderFactory factory = DocumentBuilderFactory.newInstance();
|
||||
factory.setNamespaceAware(namespaceAware);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user