mirror of
https://github.com/DSpace/DSpace.git
synced 2025-10-07 01:54:22 +00:00
Potential fix for code scanning alert no. 30: Resolving XML external entity in user-controlled data
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This commit is contained in:
@@ -235,6 +235,8 @@ public class PubmedImportMetadataSourceServiceImpl extends AbstractImportMetadat
|
|||||||
|
|
||||||
try {
|
try {
|
||||||
SAXBuilder saxBuilder = new SAXBuilder();
|
SAXBuilder saxBuilder = new SAXBuilder();
|
||||||
|
saxBuilder.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
||||||
|
saxBuilder.setFeature("http://xml.org/sax/features/external-general-entities", false);
|
||||||
Document document = saxBuilder.build(new StringReader(src));
|
Document document = saxBuilder.build(new StringReader(src));
|
||||||
Element root = document.getRootElement();
|
Element root = document.getRootElement();
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user