Description
Allowing DTD processing and external resource resolution for untrusted XML can let external entities read local files or trigger server-side requests. Setting DtdProcessing.Parse alone does not always allow external access; the XmlResolver configuration also matters.
Potential impact
- Local file disclosure, requests to internal networks, and denial of service.
Remediation
Prohibit DTD processing and set XmlResolver to null.
Examples
Before
csharp
var settings = new XmlReaderSettings {
DtdProcessing = DtdProcessing.Parse,
XmlResolver = new XmlUrlResolver()
};
After
csharp
var settings = new XmlReaderSettings {
DtdProcessing = DtdProcessing.Prohibit,
XmlResolver = null
};
Explanation:
- Before: A parser that permits external entities can expose local files or trigger server-side requests.
- After: Disable DTD processing and set
XmlResolvertonullbefore parsing untrusted XML.