Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
A security scan dinged Phoenix for an external entities attack on the XML files that Pherf creates.
We can easily work around it by disabling the inline doctype definition in the XML parser we use.