When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information
Hi @ALee665277 (Community Member) ,
The .NET ResolveUri method resolves relative file paths to absolute paths which may cause information leakage and is typically used to determine paths to load, see also excellent research done by VSR now NCCGroup: https://research.nccgroup.com/2014/05/19/xml-schema-dtd-and-entity-attacks-a-compendium-of-known-techniques/ .
Could you say more about how you're using this API in a context that would not result in XXE?
Thank you,
Boy Baukema
Thanks for the response. Yes, you have methods to restrict/prevent the reading and writing of your XML. This is what you want to prevent from a security stand point. But determining the path of your XML file may not be even related to reading or writing the XML file. You can use this method to show the possible location of the XML file which has nothing to do with reading/writing.
Hi @ALee665277 (Community Member) ,
While it is grouped with XXE this this might be better classified under CWE-201: Insertion of Sensitive Information Into Sent Data.
Please consider registering your idea with Veracode Community Ideas at https://community.veracode.com/s/ideas
Thank you,
Boy Baukema