angler-fishThe Vulnerability History Project

[1.4.x] Restrict the XML deserializer to prevent network and entity-expansion DoS attacks.

      This is a security fix. Disclosure and advisory coming shortly.
    
commit 1c60d07ba23e0350351c278ad28d0bd5aa410b40
+1 -94
-14
expand_less