mirror of https://github.com/asterisk/asterisk
The xmlReadFile XML_PARSE_NOENT flag, which allows parsing of external entities, could allow a potential XXE injection attack. Replacing it with XML_PARSE_NONET, which prevents network access, is safer. Resolves: #GHSA-85x7-54wr-vh42pull/1836/head
parent
0283157ef1
commit
eb910a7b0d
Loading…
Reference in new issue