Hacker News new | past | comments | ask | show | jobs | submit login

In the meantime, can you confirm that the disabling of XML and YAML inputs fully mitigates the RCE as well as the SQLi?

The vectors for both are the same. The term "SQLI" here is very misleading.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact