commit 91ccd1501acb1316b05a0dc010601ad85a9ebd3b
Author: Dan Prince <email address hidden>
Date: Sun Feb 3 21:54:33 2013 -0500
Add a safe_minidom_parse_string function.
Adds a new utils.safe_minidom_parse_string function and
updates external API facing Cinder modules to use it.
This ensures we have safe defaults on our incoming API XML parsing.
Internally safe_minidom_parse_string uses a ProtectedExpatParser
class to disable DTDs and entities from being parsed when using
minidom.
Reviewed: https:/ /review. openstack. org/22310 github. com/openstack/ cinder/ commit/ 91ccd1501acb131 6b05a0dc010601a d85a9ebd3b
Committed: http://
Submitter: Jenkins
Branch: master
commit 91ccd1501acb131 6b05a0dc010601a d85a9ebd3b
Author: Dan Prince <email address hidden>
Date: Sun Feb 3 21:54:33 2013 -0500
Add a safe_minidom_ parse_string function.
Adds a new utils.safe_ minidom_ parse_string function and
updates external API facing Cinder modules to use it.
This ensures we have safe defaults on our incoming API XML parsing.
Internally safe_minidom_ parse_string uses a ProtectedExpatP arser
class to disable DTDs and entities from being parsed when using
minidom.
Fixes LP Bug #1100282.
Change-Id: Iff8340033c8e8d b58184944a1bf70 5e16b8b3e03