Hi Isomorphic.
Regarding the following CVE.
CVE-2020-10683
Can you confirm you are enabling the safe, non-default behavior as recommended by OWASP, for the dom4j-1.6.1.jar dependency?
We would like to confirm there is no impact here.
Thank you
Regarding the following CVE.
CVE-2020-10683
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
We would like to confirm there is no impact here.
Thank you
Comment