modularize attribute bundles in an AttributeFilterPolicy?

Nate Klingenstein nate.klingenstein at utah.edu
Sat Feb 27 18:08:51 EST 2016


> That said, I don't really think we have a non-local model for configuration resources that is secure anyway, and as long as the resources are all under local control, I would only caution that I think if we had a way to block this, we might do it at some point.

Loading external entities scares me because I’m not sure how you would even apply a security model to it if you wanted to.  Is there anything that would make it harder or easier than the alternatives?

I recall using the stupid entity expansion trick on v2, which led to parser limits in place for that prior to release.  I don’t think Chad ever forgave me for script kiddying him.  I wouldn’t have.

https://en.wikipedia.org/wiki/Billion_laughs

I would check to see if there are similar constraints in the v3 implementation as well, but I got as far as system/conf/global-system.xml before it looked “basically the same” and the imports scared me away from further investigation.


More information about the users mailing list