
Apv271212 (Community Member) asked a question.
I'm getting the Veracode issue "611 Improper Restriction of XML External Entity Reference" in Line 4 of the below pseudo code
Line1: FileReader file = new FileReader(l_sXMLPath);
Line2: JAXBContext jaxb = JAXBContext.newInstance(<Classname>.class)
Line3: Unmarshaller unmar = jaxb.createUnmarshaller();
Line4: <Classname> addr = (Classname) unmar.unmarshal(file);
As a fix we modified the code as below
Line1: FileReader file = new FileReader(l_sXMLPath);
SAXParserFactory l_spf = SAXParserFactory.newInstance();
l_spf.setFeature("http://xml.org/sax/features/external-general-entities", false);
l_spf.setFeature("http://xml.org/sax/features/external-parameter-entities", false); l_spf.setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd", false);
Source l_fileSource = new SAXSource(l_spf.newSAXParser().getXMLReader(),new InputSource(file));
Line2: JAXBContext jaxb = JAXBContext.newInstance(<Classname>.class)
Line3: Unmarshaller unmar = jaxb.createUnmarshaller();
Line4: <Classname> addr = (Classname) unmar.unmarshal(l_fileSource);
Still veracode reports as issue. Can someone help on this?
.png)
Hello @Apv271212 (Community Member),
Thanks for your question. I've put some guidance together to help our customers navigate CWE-611. We should continue to report the flaw until all the mitigating features are enabled for the SAXParserFactory. For many cases doctypes are not commonly featured, however from your example it suggests you need to support doctypes thus the following mitigations are missing from your implementation:
```
l_spf.setFeature("http://javax.xml.XMLConstants/feature/secure-processing", true);
l_spf.setXIncludeAware(false);
```
I want to know more.