mirror of https://github.com/halo-dev/halo
Fix xml external entity vulnerability
parent
2056f528fd
commit
568e48733f
|
@ -43,6 +43,7 @@ public class WordPressMigrateUtils {
|
||||||
try {
|
try {
|
||||||
SAXReader saxReader = new SAXReader();
|
SAXReader saxReader = new SAXReader();
|
||||||
Document document = saxReader.read(fileInputStream);
|
Document document = saxReader.read(fileInputStream);
|
||||||
|
saxReader.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
|
||||||
return document.getRootElement();
|
return document.getRootElement();
|
||||||
} catch (Exception e) {
|
} catch (Exception e) {
|
||||||
throw new RuntimeException("can not get root element");
|
throw new RuntimeException("can not get root element");
|
||||||
|
|
Loading…
Reference in New Issue