cubortea
07/27/2023, 6:52 AMorg.xml.sax.SAXParseException; lineNumber: 2; columnNumber: 10; DOCTYPE is disallowed when the feature "<http://apache.org/xml/features/disallow-doctype-decl>" set to true.
Stacktrace The Error Occurred in
/app/gdh/modules/cbsecurity/interceptors/Security.cfc: line 349
347: setProperty('rulesFile',rulesFile);
348: // Read in and parse
349: xmlRules = xmlSearch(XMLParse(rulesFile),"/rules/rule");
350: // Loop And create Rules
351: for(x=1; x lte Arraylen(xmlRules); x=x+1){
called from /app/gdh/modules/cbsecurity/interceptors/Security.cfc: line 68
called from /app/gdh/modules/cbsecurity/interceptors/Security.cfc: line 107
called from /app/gdh/coldbox/system/web/context/InterceptorState.cfc: line 446
called from /app/gdh/coldbox/system/web/context/InterceptorState.cfc: line 314
called from /app/gdh/coldbox/system/web/context/InterceptorState.cfc: line 140
called from /app/gdh/coldbox/system/web/services/InterceptorService.cfc: line 154
called from /app/gdh/coldbox/system/web/services/LoaderService.cfc: line 67
called from /app/gdh/coldbox/system/Bootstrap.cfc: line 98
called from /app/gdh/Application.cfc: line 44seandaniels
07/27/2023, 5:24 PMseandaniels
07/27/2023, 5:24 PMseandaniels
07/27/2023, 5:24 PMjclausen
07/27/2023, 7:10 PMApplication.cfc. This error is from some changes Lucee made to harden XML Parsing:
/**
* XML Security Features - <https://foundeo.com/security/guide/xml-external-entities/>
*/
this.xmlFeatures = {
externalGeneralEntities : false,
secure : true,
disallowDoctypeDecl : false
};jclausen
07/27/2023, 7:10 PMjclausen
07/27/2023, 7:11 PMcbSecurity. You could also open that up and remove any DocType declaration, as well.bdw429s
07/27/2023, 10:05 PMcubortea
07/28/2023, 2:20 AM