Railsã§XMLãªã¯ã¨ã¹ãã®ãã¼ã¹ã«ä½¿ç¨ããã¦ããREXMLã«ãDoSèå¼±æ§ãçºè¦ããã¾ãããXML entity explosion attackã¨å¼ã°ããæ»æææ³ã«ãããã¦ã¼ã¶ããä¸ããããXMLã解æãããããªã¢ããªã±ã¼ã·ã§ã³ããµã¼ãã¹ä¸è½(DoS)ç¶æ ã«ãããã¨ãã§ãã¾ãã大é¨åã®Railsã¢ããªã±ã¼ã·ã§ã³ã¯ãã®æ»æã«å¯¾ãã¦èå¼±ã§ãã XML entity explosion attackã¨ããã®ã¯ãå®ä½å®£è¨ã®ä¸ã§å¥ã®å®ä½ãåç §ãããã¨ãç¹°ãè¿ãã¦å®ä½åç §ã®å¦çè² è·ãé«ããææ³ã®ããã§ãããæ²ãããã¦ãããµã³ãã«ã³ã¼ãã¯çãã§ãããå®ä½åç §ãå±éããã¨ãã¼ã¿ã¯30ã¡ã¬ãã¤ãã«ããªãã¾ããå±éã®å¦çæ¹æ³ã«ãã£ã¦ã¯ãã¡ã¢ãªãé£ãå°½ããã¦ãã¾ãã®ã§ãããã å¤é¨ããXMLãã¼ã¿ã®POSTãåãä»ãããããªãµã¤ãã¯æ³¨æâ¦â¦ã¨è¨ãããã¨ããã§ãããXMLãã¼ã¿ã®POSTãåãä»ããªãã¯ãã®
{{#tags}}- {{label}}
{{/tags}}