Skip to content

[try] fix possible XXE vulnerabilities #10193

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

xxxxxcat1
Copy link

@xxxxxcat1 xxxxxcat1 commented Apr 16, 2025

拉取/合并请求描述:(PR description)

[

为什么提交这份PR (why to submit this PR)

The original code is subject to XXE attacks.

你的解决方案是什么 (what is your solution)

Add:
from defusedxml.ElementTree import parse
from defusedxml.common import DefusedXmlException
Modified to:
tree = parse('template_vs2005.vcproj', forbid_dtd=False, forbid_external=True)

当前拉取/合并请求的状态 Intent for your PR

必须选择一项 Choose one (Mandatory):

  • 本拉取/合并请求是一个草稿版本 This PR is for a code-review and is intended to get feedback
  • 本拉取/合并请求是一个成熟版本 This PR is mature, and ready to be integrated into the repo

代码质量 Code Quality:

我在这个拉取/合并请求中已经考虑了 As part of this pull request, I've considered the following:

  • 已经仔细查看过代码改动的对比 Already check the difference between PR and old code
  • 代码风格正确,包括缩进空格,命名及其他风格 Style guide is adhered to, including spacing, naming and other styles
  • 没有垃圾代码,代码尽量精简,不包含#if 0代码,不包含已经被注释了的代码 All redundant code is removed and cleaned up
  • 所有变更均有原因及合理的,并且不会影响到其他软件组件代码或BSP All modifications are justified and not affect other components or BSP
  • 对难懂代码均提供对应的注释 I've commented appropriately where code is tricky
  • 代码是高质量的 Code in this PR is of high quality
  • 已经使用formatting 等源码格式化工具确保格式符合RT-Thread代码规范 This PR complies with RT-Thread code specification
  • 如果是新增bsp, 已经添加ci检查到.github/workflows/bsp_buildings.yml 详细请参考链接BSP自查

The original code may have had an XXE vulnerability, which is now fixed
The original code may have had an XXE vulnerability, which is now largely fixed.
@github-actions github-actions bot added the tools label Apr 16, 2025
@CLAassistant
Copy link

CLAassistant commented Apr 16, 2025

CLA assistant check
All committers have signed the CLA.

@supperthomas supperthomas requested a review from Copilot April 16, 2025 04:56
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR aims to mitigate potential XXE vulnerabilities in the XML parsing by switching from the standard ElementTree parser to defusedxml's secure parse function.

  • Replace the usage of etree.parse with defusedxml.ElementTree.parse.
  • Introduce additional imports to handle the revised parsing and exception handling.

Comment on lines +91 to +92
# tree = etree.parse('template_vs2005.vcproj')
tree = parse('template_vs2005.vcproj', forbid_dtd=False, forbid_external=True)
Copy link
Preview

Copilot AI Apr 16, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The commented-out legacy parsing code may lead to confusion; consider removing it if it's no longer needed.

Suggested change
# tree = etree.parse('template_vs2005.vcproj')
tree = parse('template_vs2005.vcproj', forbid_dtd=False, forbid_external=True)

Copilot uses AI. Check for mistakes.

@@ -86,7 +88,8 @@ def VS_AddHeadFilesGroup(program, elem, project_path):
def VSProject(target, script, program):
project_path = os.path.dirname(os.path.abspath(target))

tree = etree.parse('template_vs2005.vcproj')
# tree = etree.parse('template_vs2005.vcproj')
tree = parse('template_vs2005.vcproj', forbid_dtd=False, forbid_external=True)
Copy link
Preview

Copilot AI Apr 16, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The current configuration allows DTDs (forbid_dtd=False) which may still enable XXE attacks; if the intent is to fully mitigate XXE vulnerabilities, consider setting forbid_dtd to True.

Suggested change
tree = parse('template_vs2005.vcproj', forbid_dtd=False, forbid_external=True)
tree = parse('template_vs2005.vcproj', forbid_dtd=True, forbid_external=True)

Copilot uses AI. Check for mistakes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants