CodeQL: Disable external XML parsing in kmip-client
Open
@kamtso-jpl is already working on this.
Since Dec 11, 2025.
crit-3
security
- Dominant language
- Java
- Stars
- 5
- Forks
- 5
- Avg merge
- 6h 43m
- Merged PRs (30d)
- 5
Description
CodeQL complains about use of XML parsing without disabling external document reading in:
kmip-client/src/main/java/ch/ntb/inf/kmip/config/ContextProperties.java
public void decode() {
SAXReader xmlReader = new SAXReader();
xmlReader.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); -- add this line
}
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.