Uploaded image for project: 'Falcon'
  1. Falcon
  2. FALCON-2273

Disallow external entity injection and clean up some log messages

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • trunk, 0.10
    • trunk, 0.11
    • general
    • None

    Description

      While reviewing the Falcon code, it was found that there is a potential for an external entity to be injected during XML entity parsing.

      Also in the data source entity parsing, we would like to avoid the location of the credential files which can be potentially used for exploiting

      Attachments

        Activity

          People

            venkatnrangan Venkat Ranganathan
            venkatnrangan Venkat Ranganathan
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: