Hey all.. I'm trying out 5.4.2.17 with the XXE mit...
# lucee
c
Hey all.. I'm trying out 5.4.2.17 with the XXE mitigation. I receive XML files from trusted sources.. But I can't seem to disable the XXE mitigation.. Here is a small script that highlights my issue (trycf lucee isnt on a late enough version to demonstrate)... Am I missing something obvious? https://trycf.com/gist/a58d019b7f1374b3966dc1153128b49d/lucee6-beta?theme=monokai
z
has to be done via application.cfc this.xmlFeatures for via application action="update" neither of which work on trycf https://dev.lucee.org/t/lucee-5-4-2-and-6-0-now-has-anti-xxe-configuration-enabled-by-default/12811 Last night I knocked out a PR to add support to xmlParse for this too https://github.com/lucee/Lucee/pull/2196
🤘 2
d
@zackster That's a great pull request. It definitely seems like you should be able to disable XXE on a case-by-case basis. If you know specific XML is trusted and safe, you should be able to disable it.
❤️ 1
z
thanks mate
i need to add some test cases for the ACF compat i added in, then i'll merge it in
also added a heap of doctype tests, @mborn was having some troubles https://luceeserver.atlassian.net/browse/LDEV-4651
c
Thanks Zac.. I have disabled it in Application.cfc (see my dumps in the screenshot),, but I assumed it encompassed XmlParse..
z
I've added isXml support for xmlFeature directives as well in that PR
m
@chapmandu Your example won't work on tryCF due to application settings constraints (per Zac), but if you drop the
isXML()
from your local code it should fix the issue.
That is, if you're seeing the same issue I am.
c
Hey@mborn.. i understand tryCF won't run the code.. it was just a place to put the snippet 😉 . I'm not sure I follow why removing isXML() will fix the issue? The xmlParse still throws an exception even when
this.xmlFeatures
is disabled
m
@chapmandu ah, got it. On the isXML() comment... in my tests, running isXML() would ignore the allow doctype setting and break all further executions of xmlParse(), even when this.xmlFeatures.disallowDoctype is set to false. Removing the isXML() would cause the xmlParse () to respect the xmlFeatures settings after a server restart.
👍 1
z
this is my little local test case, which runs fine for me on tomcat / 5.4.2.20 and 6.0.0.523
💪 1
fix on the way