Skip to content

Ensure DOM parsing defaults to not expanding external entities #1279

@cowtowncoder

Description

@cowtowncoder

Since there were issues wrt general XML handling:

FasterXML/jackson-dataformat-xml#190

it would make sense to review smaller but relevant concers wrt DOM types that databind supports

http://stackoverflow.com/questions/38017676/small-fix-for-cve-2016-3720-with-older-versions-of-jackson-all-1-9-11-and-in-ja/38018454#38018454

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions