garydgregory commented on PR #2635: URL: https://github.com/apache/activemq/pull/2635#issuecomment-5982250784
Hi @mattrpav CC @ppkarwasz Commons Secure XML is a tiny library that: - Prevents XXE Attacks: It disables external entity resolution, blocking XML External Entity (XXE) vulnerabilities that lead to data exposure. - Prevents Billion Laughs Attacks: It restricts recursive entity expansion, preventing denial-of-service (DoS) attempts. - Configures standard XML parsers with safe, restrictive settings out of the box. - Eliminates manual, error-prone security configuration of DocumentBuilderFactory, SAXParserFactory, TransformerFactory, and so on HTH! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected] For further information, visit: https://activemq.apache.org/contact
