Esri / geoportal-server-harvester

Metadata Harvester for Esri Geoportal Server
http://esri.github.io/geoportal-server/
Apache License 2.0
31 stars 24 forks source link

xxe #105

Closed QiAnXinCodeSafe closed 5 years ago

QiAnXinCodeSafe commented 5 years ago

When parsing the xml string in the Cilent.java , there is no prohibition of parsing the xml external entity. The attacker may construct a malicious return data to perform the xml external entity injection attack. 图片