[ 
https://issues.apache.org/jira/browse/NUTCH-3206?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18105062#comment-18105062
 ] 

Sebastian Nagel edited comment on NUTCH-3206 at 8/16/26 7:49 AM:
-----------------------------------------------------------------

Thanks, [~lewismc]. It's definitely ok to address this, although I wouldn't 
call it "critical" It's about the Nutch configuration files, and who can write 
the configuration files can do much worse things, even without taking the 
indirection of an XXE attack. Of course, the DmozParser is different - it's a 
resource from outside.


was (Author: wastl-nagel):
Thanks, [~lewismc]. It's definitely ok to address this, although I wouldn't 
call it "critical". It's about the Nutch configuration files, and who can write 
the configuration files can do much worse things, even without taking the 
indirection of an XXE attack.

> XML parsers should not be vulnerable to XXE attacks
> ---------------------------------------------------
>
>                 Key: NUTCH-3206
>                 URL: https://issues.apache.org/jira/browse/NUTCH-3206
>             Project: Nutch
>          Issue Type: Bug
>          Components: plugin
>    Affects Versions: 1.23
>            Reporter: Lewis John McGibbney
>            Assignee: Lewis John McGibbney
>            Priority: Critical
>             Fix For: 1.24
>
>
> https://github.com/apache/nutch/security/code-scanning/24



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to