Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
XmlConfigurator: do longer allow dtd processing across all platforms …
…(LOG4NET-575) This patch fixes a security vulnerabiliy reported by Karthik Balasundaram. The security vulnerability was found in the way how log4net parses xml configuration files where it allowed to process XML External Entity Processing. An attacker could use this as an attack vector if he could modify the XML configuration file.
- Loading branch information