The XML parsing logic used by the test result plugins (JUnit XML, xUnit XML, and TRX) is vulnerable to XML…
The XML parsing logic used by the test result plugins (JUnit XML, xUnit XML, and TRX) is vulnerable to XML…: a task in LegoFlow-SWE (Harbor dataset). The application should be updated to prevent the processing of external entities and DTD (Document Type Definitions) when loading test result XML…
The task
The application should be updated to prevent the processing of external entities and DTD (Document Type Definitions) when loading test result XML files. This will ensure that untrusted test result files cannot exploit XXE vulnerabilities.
Part of Lego-X/LegoFlow-SWE.