mirror of
https://gitee.com/binary/weixin-java-tools.git
synced 2025-11-09 17:39:12 +08:00
#889 修复一些潜在的XXE漏洞代码
This commit is contained in:
@ -37,7 +37,9 @@ public class WxCryptUtil {
|
||||
@Override
|
||||
protected DocumentBuilder initialValue() {
|
||||
try {
|
||||
return DocumentBuilderFactory.newInstance().newDocumentBuilder();
|
||||
final DocumentBuilderFactory factory = DocumentBuilderFactory.newInstance();
|
||||
factory.setExpandEntityReferences(false);
|
||||
return factory.newDocumentBuilder();
|
||||
} catch (ParserConfigurationException exc) {
|
||||
throw new IllegalArgumentException(exc);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user