Req #81210 [Fbk->Asn]: Disable XML External Entities by config

From: Date: Fri, 02 Jul 2021 16:48:55 +0000
Subject: Req #81210 [Fbk->Asn]: Disable XML External Entities by config
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234777@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81210&edit=1 ID: 81210 User updated by: mail at 12live dot de Reported by: mail at 12live dot de Summary: Disable XML External Entities by config -Status: Feedback +Status: Assigned Type: Feature/Change Request Package: PHP options/info functions PHP Version: Irrelevant Assigned To: cmb Block user comment: N Private report: N New Comment: Yes correct. I want to enforce that noone can enable External Entity substitution on my environment. The security risk is far too high and I don´t want to rely on the hope that any code/library is secure enough to mitigate that risk correctly. I do not have any use case where External Entities might be needed. Probably the vast majority of users does not have such use cases. Xternal Entities are a very dangerous security risk. It should be treated adequate and it should be possible to disable that completely on system/PHP level Previous Comments: ------------------------------------------------------------------------ [2021-07-02 16:32:52] cmb@php.net As of libxml2 2.9.0, substitution of external entities is disabled by default. You need to explicitly pass XML_NOENT to the respective functions to enable it. Are you suggesting that an ini setting should make XML_NOENT to have no effect? ------------------------------------------------------------------------ [2021-06-30 11:40:24] mail at 12live dot de Can´t agree on that. Of course your code should be secure but the ini option could be another element regarding "Defense in depth". PHP already has such switches. Also if i completely run php on my own controlled environment this would help harden the environment. Especially regarding libraries beeing used where it is not always obvious that there might be a XML Ecternal Entity sink ------------------------------------------------------------------------ [2021-06-30 11:34:14] rtrtrtrtrt at dfdfdfdf dot dfd such switches are a terrible idea because you can't know where your code will run in the future - instead write good code you rely on luck of a server config which could change tomorrow ------------------------------------------------------------------------ [2021-06-30 11:29:11] mail at 12live dot de Description: ------------ As XML External Entity is still a serious security risk, i would like to have the ini option to disable this globally PHP level. Ideally it would be disabled by default (as GO does) but I can understand if this is not feasible. At least not if PHP claims to be XML standard compliant by default. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81210&edit=1

« previous php.bugs (#234777) next »