Core: XmlPullParser processes external DTD entities (XXE) — disable FEATURE_PROCESS_DOCDECL in Xml#createParser()

オープン 初心者向け
#2,179 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
84/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
静か
技術スタック
java
領域
security

調査の方向性

google-http-client-xml モジュールの Xml#createParser() から始め、新しい XmlPullParser がどのように設定されているかを確認します。Issue の DTD エンティティ例を使用して、名前付きの回帰テスト testCreateParser_disablesDocDecl を実行するか追加します。文書宣言が無効化されるか安全に拒否され、回帰テストによってエンティティが解決されないことが確認できれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Environment details

  1. Core (XML) — Xml#createParser() in google-http-client-xml
  2. OS type and version: Any (JVM-level issue, not OS-specific)
  3. Java version: Any (Java 8+)
  4. google-http-client-xml version: 2.1.1 and earlier

Problem Statement

Xml#createParser() returns a raw XmlPullParser without disabling
XmlPullParser.FEATURE_PROCESS_DOCDECL. If an attacker can influence the XML content
parsed by the library (e.g. via a malicious server response or injected content), they can
embed a <!DOCTYPE> declaration with external entity references (),
causing the parser to resolve arbitrary external entities.

This is a classic XML External Entity (XXE) vulnerability.


Steps to reproduce

  1. Call Xml.createParser() and feed it XML containing an inline DTD with entity
    declarations ( ]>).
  2. Parse the document with Xml.parseElement(...).
  3. Observe that the entity &xxe; is resolved and its value appears in the parsed output
    instead of being rejected or left unexpanded.

Code example

XmlPullParser parser = Xml.createParser();
String xmlWithDtd = "\n"
+ "\n"
+ "]>\n"
+ "&xxe;";
parser.setInput(new StringReader(xmlWithDtd));

SimpleTypeString result = new SimpleTypeString();
Xml.parseElement(parser, result, new XmlNamespaceDictionary().set("", ""), null);
// result.value == "injected" <-- DTD entity resolved, XXE confirmed


Security Impact

  • Allows entity injection / content spoofing from malicious XML input.
  • In environments parsing untrusted XML (e.g. API responses from attacker-controlled
    servers), this could lead to information disclosure or server-side request forgery (SSRF)
    if external URI entities are supported by the underlying parser implementation.

Proposed Fix

Set FEATURE_PROCESS_DOCDECL to false immediately after creating the parser, with a
graceful fallback for parsers that do not support the feature flag:

public static XmlPullParser createParser() throws XmlPullParserException {
  XmlPullParser parser = getParserFactory().newPullParser();
  try {
    parser.setFeature(XmlPullParser.FEATURE_PROCESS_DOCDECL, false);
  } catch (XmlPullParserException e) {
    // Ignore if the feature is not supported by this parser implementation
  }
  return parser;
}

A regression test (testCreateParser_disablesDocDecl) is included in the accompanying PR
verifying that DTD entity content is not resolved (or that the parser throws, which is also
an acceptable safe outcome).

主要言語
Java
スター
1.4k
フォーク
473
PR マージ指標
30日以内にマージされた PR はありません

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

googleapis/google-http-java-client のほかの issue

googleapis/google-http-java-client の issue をすべて見る

似ている issue

Java の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。