Welcome! Please see the About page for a little more info on how this works.

0 votes
in data.xml by
retagged by

As defined by OWASP recommendations [1], both supporting-external-entities and support-dtd should be disabled by default.
While it's the case for the former (but not released as part of the 0.0.8 version), it's not the case for the latter.

Can we consider having both defined to false as part of a stable version?

[1] : https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser.

2 Answers

0 votes
selected by
0 votes

By "stable" do you mean non-alpha, or non-SNAPSHOT?

According to the README, the stable version is 0.0.8, while the preview one is 0.2.0-alpha8.
I would expect either a 0.0.9 version which includes the two parameters as disabled (since it's a security issue). Or a 0.2.0 marked as the new stable version afterwards.