summaryrefslogtreecommitdiff
path: root/Doc/library/xml.etree.elementtree.rst
diff options
context:
space:
mode:
authorChristian Heimes <christian@cheimes.de>2013-03-26 17:48:28 +0100
committerChristian Heimes <christian@cheimes.de>2013-03-26 17:48:28 +0100
commit9869e60dc2e7803f31af47a37fcc6392262496d8 (patch)
tree49364ab55ba75b075d9cb2f2f624421b911862a9 /Doc/library/xml.etree.elementtree.rst
parenta1e8244afaef671d685d7d171288effa00f2c1b9 (diff)
parent768f6a53601a6c4e0b914aaedb977dd2ca97532a (diff)
downloadcpython-git-9869e60dc2e7803f31af47a37fcc6392262496d8.tar.gz
Issue 17538: Document XML vulnerabilties
Diffstat (limited to 'Doc/library/xml.etree.elementtree.rst')
-rw-r--r--Doc/library/xml.etree.elementtree.rst7
1 files changed, 7 insertions, 0 deletions
diff --git a/Doc/library/xml.etree.elementtree.rst b/Doc/library/xml.etree.elementtree.rst
index 2a9f9b30b0..6af287f1b1 100644
--- a/Doc/library/xml.etree.elementtree.rst
+++ b/Doc/library/xml.etree.elementtree.rst
@@ -12,6 +12,13 @@ for parsing and creating XML data.
This module will use a fast implementation whenever available.
The :mod:`xml.etree.cElementTree` module is deprecated.
+
+.. warning::
+
+ The :mod:`xml.etree.ElementTree` module is not secure against
+ maliciously constructed data. If you need to parse untrusted or
+ unauthenticated data see :ref:`xml-vulnerabilities`.
+
Tutorial
--------