[
https://issues.apache.org/jira/browse/BATIK-1018?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Luis Bernardo resolved BATIK-1018.
----------------------------------
Resolution: Fixed
Fix Version/s: trunk
this was disabled in trunk recently. if there is demand to make this
configurable then we can implement that feature, but by default XXE will be
disabled.
> "XML External Entities" vulnerability
> -------------------------------------
>
> Key: BATIK-1018
> URL: https://issues.apache.org/jira/browse/BATIK-1018
> Project: Batik
> Issue Type: Bug
> Components: Web Site
> Affects Versions: 1.8
> Environment: Operating System: All
> Platform: All
> Reporter: Nicolas GREGOIRE
> Assignee: Batik Developer's Mailing list
> Fix For: trunk
>
> Attachments: xxe.png, xxe.svg
>
>
> During visualization with Squiggle or rasterization via the CLI tool, XML
> external entities defined in the DTD are dereferenced and the content of the
> target file is included in the output.
> The impact of this vulnerability range form denial of service to file
> disclosure. Under Windows, it can also be used to steal LM/NTLM hashes.
> For some additional information about XXE attacks, please refer to
> http://cwe.mitre.org/data/definitions/827.html
> How to reproduce:
> $> rasterizer xxe.svg -d xxe.png
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]