33 lines
616 B
Plaintext

== How to fix it in Jdom2
=== Code examples
include::../../common/fix/code-rationale.adoc[]
==== Noncompliant code example
[source,java,diff-id=11,diff-type=noncompliant]
----
import org.jdom2.input.SAXBuilder;
public void decode() {
SAXBuilder builder = new SAXBuilder(); // Noncompliant
}
----
==== Compliant solution
[source,java,diff-id=11,diff-type=compliant]
----
import org.jdom2.input.SAXBuilder;
public void decode() {
SAXBuilder builder = new SAXBuilder();
builder.setProperty(XMLConstants.ACCESS_EXTERNAL_DTD, "");
}
----
=== How does this work?
include::../../common/fix/xxe.adoc[]