[
https://issues.apache.org/jira/browse/CAMEL-24691?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18117925#comment-18117925
]
Claus Ibsen commented on CAMEL-24691:
-------------------------------------
Fixed by https://github.com/apache/camel/pull/26344 (commit 9c23b6868bb9) on
main, fix version 4.23.0. Backports to camel-4.22.x and camel-4.18.x follow via
the port/* labels.
_Claude Code on behalf of davsclaus_
> camel-saxon - align XQueryBuilder with secure XML parsing defaults
> ------------------------------------------------------------------
>
> Key: CAMEL-24691
> URL: https://issues.apache.org/jira/browse/CAMEL-24691
> Project: Camel
> Issue Type: Bug
> Components: camel-saxon
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.23.0
>
>
> XQueryBuilder builds its default Saxon Configuration in XQueryBuilder.init()
> with only a space-stripping ParseOptions. Unlike camel-xslt-saxon (which
> defaults secureProcessing=true) and Camel's own XmlConverter, it does not
> configure the underlying XML parser features. As a result, when a message
> body reaches Saxon as an already-built javax.xml.transform.Source, it is
> parsed using the parser defaults rather than Camel's hardened ones. This is
> inconsistent with the String/byte[]/InputStream body paths (which are already
> hardened via XmlConverter) and with the recent camel-xpath change in
> CAMEL-24475.
> Configure the standard secure parser features on the default Configuration's
> ParseOptions:
> * http://apache.org/xml/features/disallow-doctype-decl = true
> * http://xml.org/sax/features/external-general-entities = false
> * http://xml.org/sax/features/external-parameter-entities = false
> * http://apache.org/xml/features/nonvalidating/load-external-dtd = false
> This aligns the Source body path with the already-hardened converter paths
> and with camel-xslt-saxon. A unit test is added, and an upgrade-guide note is
> included since Source-typed input that contains a DOCTYPE will now be
> rejected.
> Affected: components/camel-saxon (XQueryBuilder). To be backported to
> camel-4.22.x and camel-4.18.x.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)