Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix CVE-2018-1000632 by cherry-picking from e598eb43d418744c4dbf62f647dd2381c9ce9387 #73

Closed
wants to merge 0 commits into from

Conversation

harkue
Copy link

@harkue harkue commented Oct 23, 2019

Fixes #55

This CVE is not fixed on branch version-2.0.x which is still support for JDK7 instead of master.

So, I submit a PR to fix this CVE through cherry picke from commit e598eb43d418744c4dbf62f647dd2381c9ce9387:

#48 Validate QName inputs - throw IllegalArgumentException when qualified name contains disallowed character.

@harkue harkue changed the title fix CVE-2018-1000632 by cherry-pick from e598eb43d418744c4dbf62f647dd2381c9ce9387 fix CVE-2018-1000632 by cherry-picking from e598eb43d418744c4dbf62f647dd2381c9ce9387 Oct 23, 2019
@harkue harkue closed this Oct 24, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant