Completely disable xml entity resolution #614

Merged
floatingghost merged 1 commit from MaeIsBad/akkoma:completely-disable-xml-entity-resolution into develop 2023-08-05 12:36:29 +00:00
Contributor

I misunderstood how the fetch_fun option on xmerl_scan.string worked. While the previous patch was sufficient to prevent reading local files it still could be DOSed with a billion laughs attack.

I misunderstood how the fetch_fun option on xmerl_scan.string worked. While the previous patch was sufficient to prevent reading local files it still could be DOSed with a billion laughs attack.
MaeIsBad force-pushed completely-disable-xml-entity-resolution from 1c9ca126d9
Some checks are pending
ci/woodpecker/pr/build-amd64 Pipeline is pending
ci/woodpecker/pr/build-arm64 Pipeline is pending
ci/woodpecker/pr/docs Pipeline is pending
ci/woodpecker/pr/test Pipeline is pending
to d868348fac
Some checks are pending
ci/woodpecker/pr/build-amd64 Pipeline is pending
ci/woodpecker/pr/build-arm64 Pipeline is pending
ci/woodpecker/pr/docs Pipeline is pending
ci/woodpecker/pr/test Pipeline is pending
2023-08-05 12:32:08 +00:00
Compare

wowee cutting it CLOOOOSE on this one, i was literally just putting the release out - thanks a lot!

wowee cutting it CLOOOOSE on this one, i was literally just putting the release out - thanks a lot!

all tests pass, good by me!

all tests pass, good by me!
floatingghost deleted branch completely-disable-xml-entity-resolution 2023-08-05 12:36:30 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
AkkomaGang/akkoma!614
No description provided.