google / depan

DepAn is a direct manipulation tool for visualization, analysis, and refactoring of dependencies in large applications.
http://google.github.io/depan
Apache License 2.0
89 stars 20 forks source link

xxe #57

Open QiAnXinCodeSafe opened 5 years ago

QiAnXinCodeSafe commented 5 years ago

The parseDocument() in PushDownXmlHandler.java does not disable the xml external entity when parsing the xml. When the parsed resource is under the control of the attacker, the xml external entity attack may be constructed by constructing a malicious xml. 图片