mirror of
https://github.com/Alfresco/alfresco-community-repo.git
synced 2025-08-07 17:49:17 +00:00
MNT-10589: Merged V4.2-BUG-FIX (4.2.2) to V4.2.1 (4.2.1)
60891: Merged BRANCHES/DEV/V4.1-BUG-FIX to BRANCHES/DEV/V4.2-BUG-FIX: 60889: Merged BRANCHES/DEV/V3.4-BUG-FIX to BRANCHES/DEV/V4.1-BUG-FIX: 60873: MNT-10560: Security: The Apache Xerces XML parser exposes security vulnerabilities 60876: MNT-10560: Security: The Apache Xerces XML parser exposes security vulnerabilities 60887: MNT-10560: Security: The Apache Xerces XML parser exposes security vulnerabilities git-svn-id: https://svn.alfresco.com/repos/alfresco-enterprise/alfresco/PATCHES/V4.2.1/root@60909 c4b6b30b-aa2e-2d43-bbcb-ca4b014f7261
This commit is contained in:
@@ -30,6 +30,7 @@ import org.alfresco.model.WCMAppModel;
|
|||||||
import org.alfresco.repo.domain.PropertyValue;
|
import org.alfresco.repo.domain.PropertyValue;
|
||||||
import org.alfresco.service.cmr.avm.AVMNodeDescriptor;
|
import org.alfresco.service.cmr.avm.AVMNodeDescriptor;
|
||||||
import org.alfresco.service.cmr.remote.AVMRemote;
|
import org.alfresco.service.cmr.remote.AVMRemote;
|
||||||
|
import org.alfresco.util.XMLUtil;
|
||||||
import org.apache.commons.logging.Log;
|
import org.apache.commons.logging.Log;
|
||||||
import org.apache.commons.logging.LogFactory;
|
import org.apache.commons.logging.LogFactory;
|
||||||
import org.w3c.dom.Document;
|
import org.w3c.dom.Document;
|
||||||
@@ -147,10 +148,8 @@ public class FormDataFunctions
|
|||||||
DocumentBuilderFactory localDbf = dbf.get();
|
DocumentBuilderFactory localDbf = dbf.get();
|
||||||
if (localDbf == null)
|
if (localDbf == null)
|
||||||
{
|
{
|
||||||
localDbf = DocumentBuilderFactory.newInstance();
|
localDbf = XMLUtil.getDocumentBuilderFactory(true, false);
|
||||||
}
|
}
|
||||||
localDbf.setNamespaceAware(true);
|
|
||||||
localDbf.setValidating(false);
|
|
||||||
dbf.set(localDbf);
|
dbf.set(localDbf);
|
||||||
DocumentBuilder builder = localDbf.newDocumentBuilder();
|
DocumentBuilder builder = localDbf.newDocumentBuilder();
|
||||||
result = builder.parse(is);
|
result = builder.parse(is);
|
||||||
|
Reference in New Issue
Block a user