Base: Disable default entity resolution
Fixes CWE-611, guards agains XML external entity attacks.
This commit is contained in:
committed by
Kacper Donat
parent
19001d9cfe
commit
983ec3815c
@@ -2094,6 +2094,7 @@ void ParameterManager::CheckDocument() const
|
||||
parser.setValidationScheme(XercesDOMParser::Val_Auto);
|
||||
parser.setDoNamespaces(true);
|
||||
parser.setDoSchema(true);
|
||||
parser.setDisableDefaultEntityResolution(true);
|
||||
|
||||
DOMTreeErrorReporter errHandler;
|
||||
parser.setErrorHandler(&errHandler);
|
||||
|
||||
Reference in New Issue
Block a user