Improve XML External Entity (XXE) detection
@azurit ya está trabajando en esto.
Desde el 27/4/2024.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Motivation
I could be wrong but as far as I can tell, the XML External Entity (XXE) protection offered by CRS is fairly poor. There have been multiple attempts in the past to address these shortcomings but they have not succeeded and there are currently no ongoing efforts to improve the situation.
These are the issues and pull requests that have been created in the past:
- https://github.com/coreruleset/coreruleset/issues/1319
- https://github.com/coreruleset/coreruleset/issues/1320
- https://github.com/coreruleset/coreruleset/pull/2061
- https://github.com/coreruleset/coreruleset/pull/2163
From the discussions in the tickets and pull requests above, the problem appears to be that there is a shortcoming of ModSecurtiy which causes the targeted collections (REQUEST_BODY and FULL_REQUEST) to be empty if a body parser has been activated. This, of course, would be the case in most situation where XXE detection is desired, braking the proposed rules.
However, since the information related to XXEs is contained in <!DOCTYPE ...> tags, which are not accessible through the XML collection using XPath expressions, is not possible to write reliable ModSecurity rules to detect XXEs for these requests.
This issue is known but considering the following discussion, it is unlikely to be fixed in ModSecurity any time soon: https://github.com/SpiderLabs/ModSecurity/issues/2087.
There have been comments that a plugin leveraging ModSecurity's Lua capabilities might help but as far as I can tell, this was never implemented: https://github.com/coreruleset/coreruleset/pull/2163#issuecomment-997432471.
Proposed solution
Implement a plugin similar to the antivirus plugin which can reliably detect XXEs in requests independently of whether or not a body parser has been activated.
Alternatives
A cleaner approach might be to create a pull request to ModSecurity to provide additional information about the payload like the DOCTYPE through either the existing XML collection or through a new collection. This would allow for regular rules to be written in order to detect XXEs. However, this would require a change to ModSecurity, which is outside the control of the Core Rule Set Project.
Additional context
There is a ModSecurity directive related to XXEs: SecXmlExternalEntity. This directive is turned off by default. From what I understand, this directive only configures whether ModSec expands External Entities in XML or not. It does not configure whether XXEs are allowed in general or not. XML containing XXEs are not blocked, even if SecXmlExternalEntity is turned off.
There are rules that might detect XXEs in certain circumstances, however, this is mostly incidental as they do not explicitly check for XXEs.
- Lenguaje dominante
- Python
- Estrellas
- 53
- Forks
- 13
- Merge medio
- 7 h 30 min
- PR fusionados (30 d)
- 1
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de coreruleset/plugin-registry
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
Rules for AI CrawlersAbiertoenhancement help wanted
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
coreruleset/plugin-registry#44 · 10 comentarios ·
-
enhancement help wanted
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
coreruleset/plugin-registry#43 · 1 comentario ·
-
Feature Request: GitLab PluginQuizá libre de nuevo @EsadCetiner la tomó hace 262 días y no hay ningún pull request abierto. Abierto
coreruleset/plugin-registry#25 · 6 comentarios · 1 reacción · 1 asignado ·
-
Transfer GeoIP Plugin?Abierto
Dificultad 5/5 Más de una semana Aptitud para principiantes 15/100
coreruleset/plugin-registry#19 · 13 comentarios ·
Todos los issues de coreruleset/plugin-registry
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
kornia/kornia#5263 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Metadata correction for W16-5400Abiertoapproved correction metadata
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
acl-org/acl-anthology#10133 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
BasedHardware/omi#20084 ·
Los mantenedores suelen responder en 1 día
-
bug needs-acceptance wg/evaluation-quality
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
vllm-project/semantic-router#4424 ·
Los mantenedores suelen responder en 1 día