mirror of https://github.com/asterisk/asterisk
The xmlReadFile XML_PARSE_NOENT flag, which allows parsing of external entities, could allow a potential XXE injection attack. Replacing it with XML_PARSE_NONET, which prevents network access, is safer. Resolves: #GHSA-85x7-54wr-vh42pull/1790/head
parent
74d62161c5
commit
c92ae66905
Loading…
Reference in new issue