{"id":"GHSA-432c-wxpg-m4q3","aliases":[],"url":"https://o3.security/vulnerability/GHSA-432c-wxpg-m4q3","summary":"xml2rfc has file inclusion irregularities","details":"Version [3.12.0](https://github.com/ietf-tools/xml2rfc/blob/main/CHANGELOG.md#3120---2021-12-08) changed `xml2rfc` so that it would not access local files without the presence of its new `--allow-local-file-access` flag.\nThis prevented XML External Entity (XXE) injection attacks with `xinclude` and XML entity references.\n\nIt was discovered that `xml2rfc` does not respect `--allow-local-file-access` when a local file is specified as `src` in `artwork` or `sourcecode` elements. Furthermore, XML entity references can include any file inside the source dir and below without using the `--allow-local-file-access` flag. \n\nThe `xml2rfc <= 3.26.0` behaviour:\n\n|  | `xinclude` | XML entity reference | `artwork src=` | `sourcecode src=` |\n|---|---|---|---|---|\n| without `--allow-local-file-access` flag | No filesystem access | Any file in xml2rfc templates dir and below, any file in source directory and below | Access source directory and below | Access source directory and below |\n| with `--allow-local-file-access` flag | Access any file on filesystem[^1] | Access any file on filesystem[^1] | Access source directory and below | Access source directory and below | Access source directory and below |\n\n  [^1]: Access any file of the filesystem with the permissions of the user running `xml2rfc` can access.\n\n### Impact\n\nAnyone running `xml2rfc` as a service that accepts input from external users is impacted by this issue.\nSpecifying a file in `src` attribute in `artwork` or `sourcecode` elements will cause the contents of that file to appear in xml2rfc’s output results.\nBut that file has to be inside the same directory as the XML input source file.\nFor `artwork` and `sourcecode`, `xml2rfc` will not look above the source file directory.\n\n### The proposed new behaviour\n- Generalize file access checks.\n- Only allow access to files within src dir and below. (xml entity include can access templates dir).\n- Always allow access to `templates_dir` for XML entity includes.\n\nNew behaviour:\n\n|  | `xinclude` | XML entity reference | `artwork src=` | `sourcecode src=` |\n|---|---|---|---|---|\n| without `--allow-local-file-access` flag | No filesystem access | No filesystem access _(except for `templates_dir`)_ | No filesystem access | No filesystem access |\n| with `--allow-local-file-access` flag | Access source directory and below | Access source directory and below _(Can access`templates_dir`)._ | Access source directory and below | Access source directory and below |\n\n### Workarounds\n\nUse a secure temporary directory to process un-trusted XML files, and do not reuse it for processing other XML documents.","published":"2025-02-07T20:32:27Z","modified":"2025-02-07T20:36:32.770761Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"xml2rfc","fixedVersion":"3.27.0"}],"fix":{"url":"https://github.com/ietf-tools/xml2rfc/commit/ec98f9cb4b9a8658222117df037dda473ca3f4e4","label":"ietf-tools/xml2rfc@ec98f9c"},"references":[{"type":"WEB","url":"https://github.com/ietf-tools/xml2rfc/security/advisories/GHSA-432c-wxpg-m4q3"},{"type":"WEB","url":"https://github.com/ietf-tools/xml2rfc/commit/ec98f9cb4b9a8658222117df037dda473ca3f4e4"},{"type":"PACKAGE","url":"https://github.com/ietf-tools/xml2rfc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-07T20:36:32.770761Z"}}