Req #81210 [Opn]: Disable XML External Entities by config
| From: | mail at 12live dot de | Date: | Fri, 02 Jul 2021 17:54:19 +0000 |
| Subject: | Req #81210 [Opn]: Disable XML External Entities by config | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234783@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81210&edit=1
ID: 81210
User updated by: mail at 12live dot de
Reported by: mail at 12live dot de
Summary: Disable XML External Entities by config
Status: Open
Type: Feature/Change Request
Package: PHP options/info functions
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
A custom PHP in my opinion is not a solution which treats such a risk appropriately. I was hopening
that someone of PHP recognizes the potential risk. An ini option would be the right solution as it
would be available for anyone and might be helpful to mitigate such a risk. PLease note that this is
one of the higher rated risks in the OWASP Top 10.
Sadly I do not have the necessary insights to provide a sufficient RFC. So I am hoping someone might
help here.
Previous Comments:
------------------------------------------------------------------------
[2021-07-02 17:07:19] cmb@php.net
Well, you can build a custom PHP where LIBXML_NOENT is defined[1]
as 0. If you prefer the INI setting, please pursue the RFC
propcess[2].
[1] <https://heap.space/xref/PHP-7.4/ext/libxml/libxml.c?r=498eb8e0#848>
[2] <https://wiki.php.net/rfc/howto>
------------------------------------------------------------------------
[2021-07-02 16:48:55] mail at 12live dot de
Yes correct. I want to enforce that noone can enable External Entity substitution on my environment.
The security risk is far too high and I don´t want to rely on the hope that any code/library is
secure enough to mitigate that risk correctly. I do not have any use case where External Entities
might be needed. Probably the vast majority of users does not have such use cases. Xternal Entities
are a very dangerous security risk. It should be treated adequate and it should be possible to
disable that completely on system/PHP level
------------------------------------------------------------------------
[2021-07-02 16:32:52] cmb@php.net
As of libxml2 2.9.0, substitution of external entities is disabled
by default. You need to explicitly pass XML_NOENT to the
respective functions to enable it. Are you suggesting that an ini
setting should make XML_NOENT to have no effect?
------------------------------------------------------------------------
[2021-06-30 11:40:24] mail at 12live dot de
Can´t agree on that. Of course your code should be secure but the ini option could be another
element regarding "Defense in depth". PHP already has such switches. Also if i completely
run php on my own controlled environment this would help harden the environment. Especially
regarding libraries beeing used where it is not always obvious that there might be a XML Ecternal
Entity sink
------------------------------------------------------------------------
[2021-06-30 11:34:14] rtrtrtrtrt at dfdfdfdf dot dfd
such switches are a terrible idea because you can't know where your code will run in the future
- instead write good code you rely on luck of a server config which could change tomorrow
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81210
--
Edit this bug report at https://bugs.php.net/bug.php?id=81210&edit=1