Req #81210 [Opn]: Disable XML External Entities by config
| From: | mail at 12live dot de | Date: | Wed, 30 Jun 2021 11:40:24 +0000 |
| Subject: | Req #81210 [Opn]: Disable XML External Entities by config | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234699@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81210&edit=1
ID: 81210
User updated by: mail at 12live dot de
Reported by: mail at 12live dot de
Summary: Disable XML External Entities by config
Status: Open
Type: Feature/Change Request
Package: PHP options/info functions
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Can´t agree on that. Of course your code should be secure but the ini option could be another
element regarding "Defense in depth". PHP already has such switches. Also if i completely
run php on my own controlled environment this would help harden the environment. Especially
regarding libraries beeing used where it is not always obvious that there might be a XML Ecternal
Entity sink
Previous Comments:
------------------------------------------------------------------------
[2021-06-30 11:34:14] rtrtrtrtrt at dfdfdfdf dot dfd
such switches are a terrible idea because you can't know where your code will run in the future
- instead write good code you rely on luck of a server config which could change tomorrow
------------------------------------------------------------------------
[2021-06-30 11:29:11] mail at 12live dot de
Description:
------------
As XML External Entity is still a serious security risk, i would like to have the ini option to
disable this globally PHP level. Ideally it would be disabled by default (as GO does) but I can
understand if this is not feasible. At least not if PHP claims to be XML standard compliant by
default.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81210&edit=1