Java XML漏洞解决方案

1:SAXReader添加
SAXReader saxReader = new SAXReader(false);
saxReader.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
saxReader.setFeature("http://xml.org/sax/features/external-general-entities", false);
saxReader.setFeature("http://xml.org/sax/features/external-parameter-entities", false);

2:SAXBuilder添加
SAXBuilder sb = new SAXBuilder();    
sb.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
sb.setFeature("http://xml.org/sax/features/external-general-entities", false);
sb.setFeature("http://xml.org/sax/features/external-parameter-entities", false);

3:DocumentHelper改成SAXReader
SAXReader reader = new SAXReader(false);
StringReader read = new StringReader(str.trim());
reader.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
reader.setFeature("http://xml.org/sax/features/external-general-entities", false);
reader.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
Document doc = reader.read(read);

4.如果有,则删除crimson.jar

你可能感兴趣的:(Java)