You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@solr.apache.org by "Haythem Khiri (Jira)" <ji...@apache.org> on 2022/07/15 13:02:00 UTC

[jira] [Created] (SOLR-16296) Load elevate.xml, currency.xml, ... in a more secure way

Haythem Khiri created SOLR-16296:
------------------------------------

             Summary: Load elevate.xml, currency.xml, ... in a more secure way
                 Key: SOLR-16296
                 URL: https://issues.apache.org/jira/browse/SOLR-16296
             Project: Solr
          Issue Type: Improvement
      Security Level: Public (Default Security Level. Issues are Public)
            Reporter: Haythem Khiri


Solr should ensure that most XML files in a ConfigSet should be loaded in an untrusted way for security. XML files can have custom DTDs and Xinclude for ConfigSets provided externally.

This is not about changing how solrconfig.xml and schema.xml is being loaded.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscribe@solr.apache.org
For additional commands, e-mail: issues-help@solr.apache.org