Req #81210 [Asn->Opn]: Disable XML External Entities by config

From: Date: Fri, 02 Jul 2021 17:07:19 +0000
Subject: Req #81210 [Asn->Opn]: Disable XML External Entities by config
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234780@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81210&edit=1

 ID:                 81210
 Updated by:         cmb@php.net
 Reported by:        mail at 12live dot de
 Summary:            Disable XML External Entities by config
-Status:             Assigned
+Status:             Open
 Type:               Feature/Change Request
 Package:            PHP options/info functions
 PHP Version:        Irrelevant
-Assigned To:        cmb
+Assigned To:        
 Block user comment: N
 Private report:     N

 New Comment:

Well, you can build a custom PHP where LIBXML_NOENT is defined[1]
as 0.  If you prefer the INI setting, please pursue the RFC
propcess[2].

[1] <https://heap.space/xref/PHP-7.4/ext/libxml/libxml.c?r=498eb8e0#848>
[2] <https://wiki.php.net/rfc/howto>


Previous Comments:
------------------------------------------------------------------------
[2021-07-02 16:48:55] mail at 12live dot de

Yes correct. I want to enforce that noone can enable External Entity substitution on my environment.
The security risk is far too high and I don´t want to rely on the hope that any code/library is
secure enough to mitigate that risk correctly. I do not have any use case where External Entities
might be needed. Probably the vast majority of users does not have such use cases. Xternal Entities
are a very dangerous security risk. It should be treated adequate and it should be possible to
disable that completely on system/PHP level

------------------------------------------------------------------------
[2021-07-02 16:32:52] cmb@php.net

As of libxml2 2.9.0, substitution of external entities is disabled
by default.  You need to explicitly pass XML_NOENT to the
respective functions to enable it.  Are you suggesting that an ini
setting should make XML_NOENT to have no effect?

------------------------------------------------------------------------
[2021-06-30 11:40:24] mail at 12live dot de

Can´t agree on that. Of course your code should be secure but the ini option could be another
element regarding "Defense in depth". PHP already has such switches. Also if i completely
run php on my own controlled environment this would help harden the environment. Especially
regarding libraries beeing used where it is not always obvious that there might be a XML Ecternal
Entity sink

------------------------------------------------------------------------
[2021-06-30 11:34:14] rtrtrtrtrt at dfdfdfdf dot dfd

such switches are a terrible idea because you can't know where your code will run in the future
- instead write good code you rely on luck of a server config which could change tomorrow

------------------------------------------------------------------------
[2021-06-30 11:29:11] mail at 12live dot de

Description:
------------
As XML External Entity is still a serious security risk, i would like to have the ini option to
disable this globally PHP level. Ideally it would be disabled by default (as GO does) but I can
understand if this is not feasible. At least not if PHP claims to be XML standard compliant by
default. 



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81210&edit=1


Thread (7 messages)

« previous php.bugs (#234780) next »