Browse Source

Sonar Fixes - try to fix XXE warnings

git-svn-id: https://svn.apache.org/repos/asf/poi/trunk@1875860 13f79535-47bb-0310-9956-ffa450edef68
tags/before_ooxml_3rd_edition
Andreas Beeker 4 years ago
parent
commit
3cb1a38d8e
1 changed files with 2 additions and 0 deletions
  1. 2
    0
      src/java/org/apache/poi/util/XMLHelper.java

+ 2
- 0
src/java/org/apache/poi/util/XMLHelper.java View File

@@ -219,6 +219,7 @@ public final class XMLHelper {
trySet(factory::setFeature, FEATURE_SECURE_PROCESSING, true);
trySet(factory::setAttribute, ACCESS_EXTERNAL_DTD, "");
trySet(factory::setAttribute, ACCESS_EXTERNAL_STYLESHEET, "");
trySet(factory::setAttribute, ACCESS_EXTERNAL_SCHEMA, "");
return factory;
}

@@ -235,6 +236,7 @@ public final class XMLHelper {
SchemaFactory factory = SchemaFactory.newInstance(W3C_XML_SCHEMA_NS_URI);
trySet(factory::setFeature, FEATURE_SECURE_PROCESSING, true);
trySet(factory::setProperty, ACCESS_EXTERNAL_DTD, "");
trySet(factory::setProperty, ACCESS_EXTERNAL_STYLESHEET, "");
trySet(factory::setProperty, ACCESS_EXTERNAL_SCHEMA, "");
return factory;
}

Loading…
Cancel
Save