Hi,
Kindly guide how to prevent XXE attack for lucee 5.3.9.133 version? I have referred to [LDEV-1676] - Lucee and Application.cfc / <cfapplication> :: Lucee Documentation
and added all 3 properties in application.cfc, still it allows external entities and thus allows retrieval of arbitrary files.
Appreciate any help suggested.
Thanks,
SG
bdw429s
September 5, 2022, 5:25pm
2
Can you share the full code of your repro case?
Any thoughts here? let me know if any other information required…
a working example really helps, bonus points if you can provide a testbox testcase
tried the already existing testcase - TryCF.com
and still parsed the external entities, pls guide if I have set the xmlFeatures correctly here…
this.xmlFeatures
is an Application.cfc
setting, so that’s not going to work on trycf like that
So may be I can say it is the same kind of entity xxe , that can be added to xml and causes XXE vulnerability for the code even after adding the this.xmlFeatures in Application.cfc
so it is done by inserting below to soap body:
we’ve added a test case for the XXE configurations
if you think there’s a problem, please file a PR to extend the test case to demonstrate the problem?
committed 11:27AM - 07 Sep 22 UTC
Added a testcase to XML Features For LDEV-1676