Fix Python version since which external enities are not resolved by default. (GH-11237)
This commit is contained in:
parent
92330c0b6d
commit
bf99bcf56c
|
@ -25,7 +25,7 @@ events until either processing is finished or an error condition occurs.
|
|||
maliciously constructed data. If you need to parse untrusted or
|
||||
unauthenticated data see :ref:`xml-vulnerabilities`.
|
||||
|
||||
.. versionchanged:: 3.8
|
||||
.. versionchanged:: 3.7.1
|
||||
|
||||
The SAX parser no longer processes general external entities by default to
|
||||
increase security by default. To enable processing of external entities,
|
||||
|
|
|
@ -75,7 +75,7 @@ decompression bomb Safe Safe Safe S
|
|||
2. :mod:`xml.dom.minidom` doesn't expand external entities and simply returns
|
||||
the unexpanded entity verbatim.
|
||||
3. :mod:`xmlrpclib` doesn't expand external entities and omits them.
|
||||
4. Since Python 3.8, external general entities are no longer processed by
|
||||
4. Since Python 3.7.1, external general entities are no longer processed by
|
||||
default.
|
||||
|
||||
|
||||
|
|
|
@ -24,7 +24,7 @@ the SAX API.
|
|||
constructed data. If you need to parse untrusted or unauthenticated data see
|
||||
:ref:`xml-vulnerabilities`.
|
||||
|
||||
.. versionchanged:: 3.8
|
||||
.. versionchanged:: 3.7.1
|
||||
|
||||
The SAX parser no longer processes general external entities by default
|
||||
to increase security. Before, the parser created network connections
|
||||
|
|
Loading…
Reference in New Issue