modularize attribute bundles in an AttributeFilterPolicy?
Nate Klingenstein
nate.klingenstein at utah.edu
Sat Feb 27 18:08:51 EST 2016
> That said, I don't really think we have a non-local model for configuration resources that is secure anyway, and as long as the resources are all under local control, I would only caution that I think if we had a way to block this, we might do it at some point.
Loading external entities scares me because I’m not sure how you would even apply a security model to it if you wanted to. Is there anything that would make it harder or easier than the alternatives?
I recall using the stupid entity expansion trick on v2, which led to parser limits in place for that prior to release. I don’t think Chad ever forgave me for script kiddying him. I wouldn’t have.
https://en.wikipedia.org/wiki/Billion_laughs
I would check to see if there are similar constraints in the v3 implementation as well, but I got as far as system/conf/global-system.xml before it looked “basically the same” and the imports scared me away from further investigation.
More information about the users
mailing list