[security-dev] PicketLink 2.7 and XXE