Skip to content

Secure XML processing

Latest
Compare
Choose a tag to compare
@runeflobakk runeflobakk released this 02 Nov 17:49
0b146da

This release ensures that XML DOCTYPE declarations are denied when parsing, which is to mitigate the possibility for XML External Entity attacks. This is mainly to secure the Posten signering API, because the signature-api-specification-jaxb is used when parsing (unmarshalling) the requests from clients.