Comment 80 for bug 1100282

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to cinder (master)

Reviewed: https://review.openstack.org/22310
Committed: http://github.com/openstack/cinder/commit/91ccd1501acb1316b05a0dc010601ad85a9ebd3b
Submitter: Jenkins
Branch: master

commit 91ccd1501acb1316b05a0dc010601ad85a9ebd3b
Author: Dan Prince <email address hidden>
Date: Sun Feb 3 21:54:33 2013 -0500

    Add a safe_minidom_parse_string function.

    Adds a new utils.safe_minidom_parse_string function and
    updates external API facing Cinder modules to use it.
    This ensures we have safe defaults on our incoming API XML parsing.

    Internally safe_minidom_parse_string uses a ProtectedExpatParser
    class to disable DTDs and entities from being parsed when using
    minidom.

    Fixes LP Bug #1100282.

    Change-Id: Iff8340033c8e8db58184944a1bf705e16b8b3e03