Skip to content

Set XmlResolver syndication.axd#207

Merged
rxtur merged 1 commit into
BlogEngine:masterfrom
irbishop:syndication-xxe
Apr 23, 2019
Merged

Set XmlResolver syndication.axd#207
rxtur merged 1 commit into
BlogEngine:masterfrom
irbishop:syndication-xxe

Conversation

@irbishop

Copy link
Copy Markdown
Contributor

Could do:

{ XmlResolver = new XmlSafeResolver() }

But I couldn't think of a valid case to allow external entities.

@irbishop

Copy link
Copy Markdown
Contributor Author

This was identified while patching the others. It will be CVE-2019-11392.

@rxtur rxtur merged commit 3a293d6 into BlogEngine:master Apr 23, 2019
@irbishop irbishop deleted the syndication-xxe branch June 1, 2019 22:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants