<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 20:55:30 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[YANGTOOLS-1211] Can XML injection protection settings be added to XmlParserStream.java?</title>
                <link>https://jira.opendaylight.org/browse/YANGTOOLS-1211</link>
                <project id="10188" key="YANGTOOLS">yangtools</project>
                    <description>&lt;p&gt;Can XML injection protection settings be added to XmlParserStream.java? For example:&lt;br/&gt;
final TransformerFactory tf = TransformerFactory.newInstance();&lt;br/&gt;
tf.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);&lt;/p&gt;</description>
                <environment></environment>
        <key id="33752">YANGTOOLS-1211</key>
            <summary>Can XML injection protection settings be added to XmlParserStream.java?</summary>
                <type id="10100" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10310&amp;avatarType=issuetype">Improvement</type>
                                            <priority id="4" iconUrl="https://jira.opendaylight.org/images/icons/priorities/minor.svg">Low</priority>
                        <status id="1" iconUrl="https://jira.opendaylight.org/images/icons/statuses/open.png" description="The issue is open and ready for the assignee to start work on it.">Open</status>
                    <statusCategory id="2" key="new" colorName="blue-gray"/>
                                    <resolution id="-1">Unresolved</resolution>
                                        <assignee username="-1">Unassigned</assignee>
                                    <reporter username="marchmuch">march much</reporter>
                        <labels>
                    </labels>
                <created>Mon, 25 Jan 2021 13:23:47 +0000</created>
                <updated>Mon, 25 Jan 2021 14:36:01 +0000</updated>
                                                                                <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                                                                <comments>
                            <comment id="68938" author="rovarga" created="Mon, 25 Jan 2021 14:36:01 +0000"  >&lt;p&gt;I do not see how it could be attacked even today. The transformer does not process a raw document, but rather a stream of events coming from a (I am pretty sure) secured XMLStreamWriter. By the time the transformer sees it, the document&apos;s contents should&apos;ve been defanged.&lt;/p&gt;

&lt;p&gt;If not, please provide a test case.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i03wu7:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>