OWASP / CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
https://cheatsheetseries.owasp.org
Creative Commons Attribution Share Alike 4.0 International
27.08k stars 3.79k forks source link

Update: [XML External Entity Prevention Cheat Sheet] #1354

Open wittjoe1 opened 4 months ago

wittjoe1 commented 4 months ago

What is missing or needs to be updated?

The chapter on .net refers to version 4.5 - nobody should really be using that anymore. It contains references to dotnet_security_unit_testing - this project was created over 7 years ago. Is this still up to date or would it not be better to exclude it in order to avoid a false sense of security?

The chapter on iOS is "up to date" with iOS 6 from 2012

How should this be resolved?

Can you please check whether some of the content is now obsolete? As I am neither a specialist for .net nor for iOS, this should not be my cup of tea...

jmanico commented 3 months ago

We accept PR's for sure. Thank you for pointing this out. Can we just remove that old content for now? What do you suggest?

wittjoe1 commented 3 months ago

Unfortunatly i really don't know - im just translating this Cheat Sheet for my company using DeepL and Brain.exe when i recognized, that these passages are likely out of date (just my 2 cents)...