Skip to content

Vulnerable to XML Entity Expansion Injection? #626

Answered by markstos
UIDecypher asked this question in Q&A
Discussion options

You must be logged in to vote

@UIDecypher This a volunteer-staffed project and we would welcome your help investigating this. By reviewing the source, you can confirm which libraries we use for XML parsing, and then visit the projects for the dependency and confirm if they are patched for this issue.

I'm also moving this to a "Discussion" for now, because you are asking if the project is vulnerable, not reporting that you've confirmed that it is.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@markstos
Comment options

@jupenur
Comment options

@markstos
Comment options

Answer selected by markstos
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
3 participants
Converted from issue

This discussion was converted from issue #624 on July 28, 2021 13:33.