Disabled XML external entity references to resolve XML external entity
vulnerability in 'SvcLogicParser.java'
Issue-ID: CCSDK-3323
Signed-off-by: Jonathan Platt <jonathan.platt@att.com>
Change-Id: Ic4a6a13e228a699abf60181a537198913900cec7
}
SAXParserFactory factory = SAXParserFactory.newInstance();
+ // To remediate XML external entity vulnerability, completely disable external entities declarations:
+ factory.setFeature("http://xml.org/sax/features/external-general-entities", false);
+ factory.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
if (schema != null) {
factory.setNamespaceAware(true);