[GitHub] [nifi] thenatog commented on issue #3507: NIFI-6301 - Added a SafeXMLConfiguration which disables XML DTDs whic…

2019-06-12 Thread GitBox
thenatog commented on issue #3507: NIFI-6301 - Added a SafeXMLConfiguration which disables XML DTDs whic… URL: https://github.com/apache/nifi/pull/3507#issuecomment-501397091 @alopresto I've verified the issue you had with the validator still running even after the controller service is

[GitHub] [nifi] thenatog commented on issue #3507: NIFI-6301 - Added a SafeXMLConfiguration which disables XML DTDs whic…

2019-06-06 Thread GitBox
thenatog commented on issue #3507: NIFI-6301 - Added a SafeXMLConfiguration which disables XML DTDs whic… URL: https://github.com/apache/nifi/pull/3507#issuecomment-499545026 I've added an XXE validator to the CommonsConfigurationLookupService to do a simple check if the file contains an