You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@tomcat.apache.org by bu...@apache.org on 2005/10/27 05:48:19 UTC

DO NOT REPLY [Bug 37261] New: - Parsing web.xml from TldLocationsCache does not handle external entities

DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG�
RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT
<http://issues.apache.org/bugzilla/show_bug.cgi?id=37261>.
ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND�
INSERTED IN THE BUG DATABASE.

http://issues.apache.org/bugzilla/show_bug.cgi?id=37261

           Summary: Parsing web.xml from TldLocationsCache does not handle
                    external entities
           Product: Tomcat 5
           Version: 5.5.9
          Platform: All
        OS/Version: All
            Status: NEW
          Severity: normal
          Priority: P2
         Component: Jasper
        AssignedTo: tomcat-dev@jakarta.apache.org
        ReportedBy: greg.peterson@essential.com.au


This is similar to bug 34034.  The org.apache.jasper.compiler.TldLocationsCache
class parses the web.xml (again!).  The processWebDotXml method of this class
should be modified to create an InputSource over the InputStream, and set the
systemId of the InputSource to the URI of the web.xml document, similar to the
change made to org.apache.jaspser.compiler.JspConfig for bug 34034.

-- 
Configure bugmail: http://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org