Uploaded image for project: 'Jackrabbit Content Repository'
  1. Jackrabbit Content Repository
  2. JCR-1355

XML import should not access external entities

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 0.9, 1.0, 1.0.1, 1.1, 1.1.1, 1.2.1, 1.2.2, 1.2.3, 1.3, 1.3.1, 1.3.3, 1.4
    • commons 1.4.2, 1.5
    • jackrabbit-jcr-commons, xml
    • None

    Description

      With current Jackrabbit the following XML document can not be imported:

      <!DOCTYPE foo SYSTEM "http://invalid.address/"><foo/>

      Even if the DTD address (or some other external resource referenced in the XML document) is correct, I don't think importXML() should even try resolving those references.

      Attachments

        Activity

          People

            jukkaz Jukka Zitting
            jukkaz Jukka Zitting
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: