Req #81210 [Opn]: Disable XML External Entities by config

From: Date: Fri, 02 Jul 2021 17:54:19 +0000
Subject: Req #81210 [Opn]: Disable XML External Entities by config
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234783@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81210&edit=1 ID: 81210 User updated by: mail at 12live dot de Reported by: mail at 12live dot de Summary: Disable XML External Entities by config Status: Open Type: Feature/Change Request Package: PHP options/info functions PHP Version: Irrelevant Block user comment: N Private report: N New Comment: A custom PHP in my opinion is not a solution which treats such a risk appropriately. I was hopening that someone of PHP recognizes the potential risk. An ini option would be the right solution as it would be available for anyone and might be helpful to mitigate such a risk. PLease note that this is one of the higher rated risks in the OWASP Top 10. Sadly I do not have the necessary insights to provide a sufficient RFC. So I am hoping someone might help here. Previous Comments: ------------------------------------------------------------------------ [2021-07-02 17:07:19] cmb@php.net Well, you can build a custom PHP where LIBXML_NOENT is defined[1] as 0. If you prefer the INI setting, please pursue the RFC propcess[2]. [1] <https://heap.space/xref/PHP-7.4/ext/libxml/libxml.c?r=498eb8e0#848> [2] <https://wiki.php.net/rfc/howto> ------------------------------------------------------------------------ [2021-07-02 16:48:55] mail at 12live dot de Yes correct. I want to enforce that noone can enable External Entity substitution on my environment. The security risk is far too high and I don´t want to rely on the hope that any code/library is secure enough to mitigate that risk correctly. I do not have any use case where External Entities might be needed. Probably the vast majority of users does not have such use cases. Xternal Entities are a very dangerous security risk. It should be treated adequate and it should be possible to disable that completely on system/PHP level ------------------------------------------------------------------------ [2021-07-02 16:32:52] cmb@php.net As of libxml2 2.9.0, substitution of external entities is disabled by default. You need to explicitly pass XML_NOENT to the respective functions to enable it. Are you suggesting that an ini setting should make XML_NOENT to have no effect? ------------------------------------------------------------------------ [2021-06-30 11:40:24] mail at 12live dot de Can´t agree on that. Of course your code should be secure but the ini option could be another element regarding "Defense in depth". PHP already has such switches. Also if i completely run php on my own controlled environment this would help harden the environment. Especially regarding libraries beeing used where it is not always obvious that there might be a XML Ecternal Entity sink ------------------------------------------------------------------------ [2021-06-30 11:34:14] rtrtrtrtrt at dfdfdfdf dot dfd such switches are a terrible idea because you can't know where your code will run in the future - instead write good code you rely on luck of a server config which could change tomorrow ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81210 -- Edit this bug report at https://bugs.php.net/bug.php?id=81210&edit=1

« previous php.bugs (#234783) next »