[OpenNMS/opennms] 32376e: NMS-20206: Handle some more review comments
Chandra Gorantla via opennms-cvs <[email protected]>
| Newsgroups | gmane.network.opennms.cvs |
|---|---|
| Message-ID | <OpenNMS/opennms/push/refs/heads/cg/jira/NMS-20206/[email protected]> |
Branch: refs/heads/cg/jira/NMS-20206
Home: https://github.com/OpenNMS/opennms
Commit: 32376ef30fd9da327560dcc354b68df73f1ff408
https://github.com/OpenNMS/opennms/commit/32376ef30fd9da327560dcc354b68df73f1ff408
Author: Chandra Gorantla <[email protected]>
Date: 2026-08-12 (Wed, 12 Aug 2026)
Changed paths:
M protocols/xml/src/main/java/org/opennms/protocols/xml/collector/AbstractXmlCollectionHandler.java
M protocols/xml/src/test/java/org/opennms/protocols/xml/collector/AbstractXmlCollectionHandlerTest.java
Log Message:
-----------
NMS-20206: Handle some more review comments
Disable external entity/DTD resolution in the DocumentBuilder and, for the
xslt-source-file path, parse the stylesheet and collected source through a
hardened XMLReader (SAXSource) so XXE is blocked even under Xalan. Adds
regression tests.
To unsubscribe from these emails, change your notification settings at https://github.com/OpenNMS/opennms/settings/notifications
_______________________________________________
Please read the OpenNMS Mailing List FAQ:
http://www.opennms.org/wiki/index.php?page=MailingListFaq
opennms-cvs mailing list
To *unsubscribe* or change your subscription options, see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-cvs