cerner / ccl-testing

A collection of maven plugins and their dependencies to perform CCL Unit tests and static analyses and to generate reports from the results.
Apache License 2.0
16 stars 11 forks source link

Missing XML Validation #39

Open QiAnXinCodeSafe opened 4 years ago

QiAnXinCodeSafe commented 4 years ago

https://github.com/cerner/ccl-testing/blob/e62f1f8d30ca8e6a55570b0236b343188125c9f1/cerreal-maven-plugin/src/main/java/com/cerner/ccl/testing/xsl/XslAPI.java#L133

Failure to enable validation when parsing XML gives an attacker the opportunity to supply malicious input.