Completely disable xml entity resolution #614

Merged
floatingghost merged 1 commits from MaeIsBad/akkoma:completely-disable-xml-entity-resolution into develop 2023-08-05 12:36:29 +00:00
Contributor

I misunderstood how the fetch_fun option on xmerl_scan.string worked. While the previous patch was sufficient to prevent reading local files it still could be DOSed with a billion laughs attack.

I misunderstood how the fetch_fun option on xmerl_scan.string worked. While the previous patch was sufficient to prevent reading local files it still could be DOSed with a billion laughs attack.
MaeIsBad force-pushed completely-disable-xml-entity-resolution from 1c9ca126d9 to d868348fac 2023-08-05 12:32:08 +00:00 Compare

wowee cutting it CLOOOOSE on this one, i was literally just putting the release out - thanks a lot!

wowee cutting it CLOOOOSE on this one, i was literally just putting the release out - thanks a lot!

all tests pass, good by me!

all tests pass, good by me!
floatingghost merged commit 643e7dd7c1 into develop 2023-08-05 12:36:29 +00:00
floatingghost deleted branch completely-disable-xml-entity-resolution 2023-08-05 12:36:30 +00:00
Sign in to join this conversation.
No description provided.