Uploaded image for project: 'Policy Framework'
  1. Policy Framework
  2. POLICY-1510

Investigate Apex dom4j

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Not Done
    • Icon: Medium Medium
    • None
    • None
    • None

      As requested by Security subcommittee, tracking false positives.

      This dependency is pulled in by hibernate-core. We are using the latest release of Hibernate (as of Casablanca Maintenance Release).

      The XML schema of incoming events is controlled in Apex and arbitrary code even if it was injected cannot be executed.

            Unassigned Unassigned
            pdragosh pdragosh
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: