Details
-
Bug
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
1.21.1
-
None
Description
Drill's XML reader would allow a maliciously crafted XML file to perform an XML eXternal Entity injection (XXE) attack. This fix disables DTD parsing in the XML format plugin and prevents XXE attacks.