jmestwa-coder opened a new pull request, #4366:
URL: https://github.com/apache/logging-log4j2/pull/4366

   Log4j Core `XmlConfiguration` blocks external entities for its 
`DocumentBuilderFactory` (`disableDtdProcessing`) but leaves the strict-mode 
schema validation path unrestricted:
   
   - `SchemaFactory` and the `Validator` set no restrictions, so a config 
loaded with `strict="true"` and a `schema` has external DTDs and entities from 
its DOCTYPE resolved during `validator.validate(...)`
   - pointing an external `SYSTEM` DTD at a local socket confirms it: before 
this change the validator connects to fetch it, after it does not (a 
nonexistent target reads/throws, a real one is read)
   - `disableExternalResolution` sets `FEATURE_SECURE_PROCESSING` and empty 
`accessExternalDTD`/`accessExternalSchema` on the factory and validator, 
matching the existing `disableDtdProcessing` restrictions
   
   Regression test and changelog entry included.
   
   ## Checklist
   
   - [x] Based on the `2.x` branch
   - [x] Non-trivial changes contain an entry file in the 
`src/changelog/.2.x.x` directory
   - [x] Tests are provided
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to