- The
rb/xxequery has been updated to add the following sinks for XML external entity expansion:- Calls to parse XML using
LibXMLwhen itsdefault_substitute_entitiesoption is enabled. - Uses of the Rails methods
ActiveSupport::XmlMini.parse,Hash.from_xml, andHash.from_trusted_xmlwhenActiveSupport::XmlMiniis configured to useLibXMLas its backend, and itsdefault_substitute_entitiesoption is enabled.
- Calls to parse XML using