Skip to content

Commit 7e8d836

Browse files
authored
Merge pull request #3251 from mybatis/autofix/alert-6-2d7812d9b9
Fix code scanning alert no. 6: Resolving XML external entity in user-controlled data
2 parents 2967694 + 650146b commit 7e8d836

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/main/java/org/apache/ibatis/parsing/XPathParser.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -237,7 +237,7 @@ private Document createDocument(InputSource inputSource) {
237237
factory.setIgnoringComments(true);
238238
factory.setIgnoringElementContentWhitespace(false);
239239
factory.setCoalescing(false);
240-
factory.setExpandEntityReferences(true);
240+
factory.setExpandEntityReferences(false);
241241

242242
DocumentBuilder builder = factory.newDocumentBuilder();
243243
builder.setEntityResolver(entityResolver);

0 commit comments

Comments
 (0)