Skip to content

Use XMLHelper for secure XML processing in DBWS XRServiceFactory and ProviderHelper - #2736

Merged
arjantijms merged 2 commits into
eclipse-ee4j:masterfrom
SebTardif:fix/xxe-xrservicefactory-secure-xml-processing
Sep 22, 2026
Merged

arjantijms merged 2 commits into
eclipse-ee4j:masterfrom
SebTardif:fix/xxe-xrservicefactory-secure-xml-processing

Conversation

@SebTardif

@SebTardif SebTardif commented May 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

XRServiceFactory.getDocumentBuilder() and getTransformer() create DocumentBuilderFactory and TransformerFactory via newInstance() without setting FEATURE_SECURE_PROCESSING, making them vulnerable to XXE attacks. The project already has XMLHelper with createDocumentBuilderFactory() and createTransformerFactory() that properly configure secure processing.

ProviderHelper.init() also creates a TransformerFactory directly without secure processing.

Changes

  • XRServiceFactory.getDocumentBuilder(): Replace DocumentBuilderFactory.newInstance() with XMLHelper.createDocumentBuilderFactory(false). This also sets namespaceAware(true) internally, so the explicit call is removed.
  • XRServiceFactory.getTransformer(): Replace TransformerFactory.newInstance() with XMLHelper.createTransformerFactory(false).
  • ProviderHelper.init(): Replace TransformerFactory.newInstance() with XMLHelper.createTransformerFactory(false).

All three changes delegate to the existing XMLHelper infrastructure that the rest of the codebase uses for secure XML factory creation.

Testing

  • DBWS module compiles successfully
  • All DBWS integration tests pass (10 tests, 0 failures)

Related

  • Related to #1613 (ObjectInputFilter for FileBasedProjectCache), which addressed a similar pattern of missing security configuration in another module.

Signed-off-by: Sebastien Tardif SebTardif@ncf.ca

@SebTardif
SebTardif force-pushed the fix/xxe-xrservicefactory-secure-xml-processing branch 2 times, most recently from a3552d6 to 3302ea1 Compare May 6, 2026 17:52
@robertpatrick

robertpatrick commented Sep 13, 2026 •

Copy link
Copy Markdown

@SebTardif The change looks straightforward, and the existing integration coverage provides useful reassurance about normal DBWS behavior.

Before merging, could you please:

  • Refresh the branch against the current master branch.
  • Add small, database-free regression tests through XRServiceFactory.getDocumentBuilder() and getTransformer(), confirming that ordinary, namespaced XML still works and external entities are not resolved under the default security configuration.

One test-wiring detail: DBWS currently skips Surefire and explicitly selects Failsafe suites, so please ensure the new tests are included in an execution that CI actually runs.

…ProviderHelper

XRServiceFactory.getDocumentBuilder() and getTransformer() create
DocumentBuilderFactory and TransformerFactory via newInstance() without
setting FEATURE_SECURE_PROCESSING. The project already has XMLHelper
with createDocumentBuilderFactory() and createTransformerFactory() that
properly configure secure processing.

ProviderHelper.init() also creates a TransformerFactory directly
without secure processing.

This change replaces all three bare newInstance() calls with their
XMLHelper equivalents, ensuring consistent XXE protection across the
DBWS module.

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
Cover namespaced parse/transform and blocked external entities
through getDocumentBuilder() and getTransformer(). Register the
suite in the Failsafe include list CI runs.

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@SebTardif
SebTardif force-pushed the fix/xxe-xrservicefactory-secure-xml-processing branch from 3302ea1 to 46a1c6f Compare September 13, 2026 18:15
@SebTardif

Copy link
Copy Markdown
Contributor Author

@robertpatrick

Before merging, could you please:

  • Refresh the branch against the current master branch.
  • Add small, database-free regression tests through XRServiceFactory.getDocumentBuilder() and getTransformer(), confirming that ordinary, namespaced XML still works and external entities are not resolved under the default security configuration.

Yes. The branch is rebased on current master, and Failsafe now runs XRServiceFactorySecureXmlTestSuite without a database.

The suite is in the existing test-dbws include list (Surefire stays skipped). It checks namespaced parse and identity transform, and that file-backed external entities are not resolved under the default XMLHelper configuration.

@robertpatrick

Copy link
Copy Markdown

@arjantijms LGTM

@arjantijms arjantijms added this to the 5.0.2 milestone Sep 22, 2026
@arjantijms arjantijms self-assigned this Sep 22, 2026
@arjantijms

Copy link
Copy Markdown
Contributor

Thanks @robertpatrick and @SebTardif The tests pass, so let's merge this

@arjantijms
arjantijms merged commit 3a497ae into eclipse-ee4j:master Sep 22, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants