This commit is contained in:
Renzo Kottmann 2019-07-01 15:54:02 +02:00
parent 5820be63e5
commit 11fb43cb37

View file

@ -10,4 +10,5 @@ Some information on how we aim to ensure certain level of quality.
## XML-Security Best Practices ## XML-Security Best Practices
* We follow the [OWASP recommendations](https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/XML_Security_Cheat_Sheet.md) on best practices for JAVA XML to mitigate XML eXternal Entity (XXE) attacks and per default we do not allow external references on Entities and XIncludes * We follow the [OWASP recommendations](https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/XML_Security_Cheat_Sheet.md)
on best practices for JAVA XML to mitigate XML eXternal Entity (XXE) attacks and we do not allow external references on Entities and XIncludes per default.