Skip to content

Conversation

@bhaveshamre
Copy link
Contributor

What changes were proposed in this pull request?

This pull request fixes a critical XML External Entity (XXE) injection vulnerability reported by Fortify.
The XML parsing and transformation logic in XmlConfigChanger.java was secured by disabling external entity processing, disallowing DOCTYPE declarations, and enabling secure processing on the TransformerFactory.

How was this patch tested?

Verified successful using: mvn clean compile package install

@bhaveshamre bhaveshamre marked this pull request as ready for review February 2, 2026 10:09
@bhaveshamre bhaveshamre marked this pull request as draft February 2, 2026 10:09
@dhavalshah9131 dhavalshah9131 marked this pull request as ready for review February 2, 2026 10:17
@dhavalshah9131 dhavalshah9131 merged commit 5ea59e0 into apache:master Feb 4, 2026
6 of 8 checks passed
Copy link
Contributor

@dhavalshah9131 dhavalshah9131 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants