[
https://issues.apache.org/jira/browse/NUTCH-3206?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18105062#comment-18105062
]
Sebastian Nagel edited comment on NUTCH-3206 at 8/16/26 7:49 AM:
-----------------------------------------------------------------
Thanks, [~lewismc]. It's definitely ok to address this, although I wouldn't
call it "critical" It's about the Nutch configuration files, and who can write
the configuration files can do much worse things, even without taking the
indirection of an XXE attack. Of course, the DmozParser is different - it's a
resource from outside.
was (Author: wastl-nagel):
Thanks, [~lewismc]. It's definitely ok to address this, although I wouldn't
call it "critical". It's about the Nutch configuration files, and who can write
the configuration files can do much worse things, even without taking the
indirection of an XXE attack.
> XML parsers should not be vulnerable to XXE attacks
> ---------------------------------------------------
>
> Key: NUTCH-3206
> URL: https://issues.apache.org/jira/browse/NUTCH-3206
> Project: Nutch
> Issue Type: Bug
> Components: plugin
> Affects Versions: 1.23
> Reporter: Lewis John McGibbney
> Assignee: Lewis John McGibbney
> Priority: Critical
> Fix For: 1.24
>
>
> https://github.com/apache/nutch/security/code-scanning/24
--
This message was sent by Atlassian Jira
(v8.20.10#820010)