Apv271212 (Community Member) asked a question.

Veracode issue "611 Improper Restriction of XML External Entity Reference"

I'm getting the Veracode issue "611 Improper Restriction of XML External Entity Reference" in Line 4 of the below pseudo code

Line1: FileReader file = new FileReader(l_sXMLPath);

Line2: JAXBContext jaxb = JAXBContext.newInstance(<Classname>.class)

Line3:  Unmarshaller unmar = jaxb.createUnmarshaller();

Line4:  <Classname> addr = (Classname) unmar.unmarshal(file);

 

As a fix we modified the code as below

 

Line1: FileReader file = new FileReader(l_sXMLPath);

 

SAXParserFactory l_spf = SAXParserFactory.newInstance();

l_spf.setFeature("http://xml.org/sax/features/external-general-entities", false);

l_spf.setFeature("http://xml.org/sax/features/external-parameter-entities", false); l_spf.setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd", false);

Source l_fileSource = new SAXSource(l_spf.newSAXParser().getXMLReader(),new InputSource(file));

 

Line2: JAXBContext jaxb = JAXBContext.newInstance(<Classname>.class)

Line3:   Unmarshaller unmar = jaxb.createUnmarshaller();

Line4:   <Classname> addr = (Classname) unmar.unmarshal(l_fileSource);

 

Still veracode reports as issue. Can someone help on this?


  • Anthony Fielding (Veracode)

    Hello @Apv271212 (Community Member)​,

    Thanks for your question. I've put some guidance together to help our customers navigate CWE-611. We should continue to report the flaw until all the mitigating features are enabled for the SAXParserFactory. For many cases doctypes are not commonly featured, however from your example it suggests you need to support doctypes thus the following mitigations are missing from your implementation:

     

    ```

    l_spf.setFeature("http://javax.xml.XMLConstants/feature/secure-processing", true);

    l_spf.setXIncludeAware(false);

    ```

    Expand Post

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.