-
-
Notifications
You must be signed in to change notification settings - Fork 222
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Ensure that defaults for XMLInputFactory
have expansion of external parsed general entities disabled [CVE-2016-3720]
#190
Comments
Will you update the corresponding entry in the NVD with fix versions? |
@astellingwerf I had nothing to do with filing CVEs in question nor have access. I have tried contacting Red Hat and we'll see where that leads. If anyone has contacts to follow up with that would be helpful. |
Have also followed up with RH via their ticket that filed the vulnerability - https://bugzilla.redhat.com/show_bug.cgi?id=1328427 |
@brettcave thank you for your help with bugzilla entry. 2.7.4 is the version here; and 2.8.0 includes fixed default settings. |
Thanks @cowtowncoder . Both 2.7.4 and 2.8.0 still fail CVE / OWASP checks as the database needs to be updated, waiting on RH to update it, assuming it was logged based on their bugzilla issue. |
FWTW this is related to http://www.cvedetails.com/cve/CVE-2016-3720 |
XMLInputFactory
have expansion of external parsed general entities disabledXMLInputFactory
have expansion of external parsed general entities disabled [CVE-2016-3720]
To reduce likelihood of malicious XXE, let's ensure that
XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES
is disabled by default when instantiate by Jackson.The text was updated successfully, but these errors were encountered: