Skip to content

Conversation

MarkBaker
Copy link
Member

This is:

- [ ] a bugfix
- [ ] a new feature
- [X] security

Checklist:

Why this change is needed?

Security fix for CVE-2019-12331

@MarkBaker MarkBaker merged commit 0e6238c into master Jun 30, 2019
@MarkBaker MarkBaker deleted the CVE-2019-12331 branch June 30, 2019 22:55
BlackyTay pushed a commit to BlackyTay/PhpSpreadsheet that referenced this pull request Aug 8, 2025
* Detect doubly-encoded xml to hide XXE attacks
Correct use of LibXml_Disable_Entity_Loader

* New test for double-encoded xml in security scanner
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

1 participant