[
https://issues.apache.org/jira/browse/CAMEL-24475?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109198#comment-18109198
]
Claus Ibsen commented on CAMEL-24475:
-------------------------------------
Fixed via https://github.com/apache/camel/pull/25683 (commit 1ead256f1bfc).
Resolving to sync JIRA status with the merged fix.
_Claude Code on behalf of Claus Ibsen_
> camel-xpath - documentType=InputSource evaluates the payload with an
> unhardened XML parser
> ------------------------------------------------------------------------------------------
>
> Key: CAMEL-24475
> URL: https://issues.apache.org/jira/browse/CAMEL-24475
> Project: Camel
> Issue Type: Bug
> Components: camel-core
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.23.0
>
>
> {{XPathBuilder}} resolves the message payload to the configured
> {{documentType}} before evaluating the expression.
> With the default {{documentType}} of {{org.w3c.dom.Document}} the type
> converter builds the DOM through
> {{XMLConverterHelper.createDocumentBuilderFactory()}}, which sets
> {{FEATURE_SECURE_PROCESSING}}, {{disallow-doctype-decl}} and
> {{external-general-entities=false}}, and empties {{ACCESS_EXTERNAL_DTD}} /
> {{ACCESS_EXTERNAL_SCHEMA}}.
> When {{documentType}} is set to {{org.xml.sax.InputSource}}, the resolved
> object is handed straight to {{XPathExpression.evaluate(InputSource, ...)}}.
> There are four such sites in {{XPathBuilder}}:
> * {{doInEvaluateAsNodeList}} - {{evaluate(inputSource,
> XPathConstants.NODESET)}}
> * the {{SAXSource}} branch of the same method -
> {{evaluate(source.getInputSource(), XPathConstants.NODESET)}}, which discards
> the reader the {{SAXSource}} carries
> * {{doInEvaluateAs}} - {{evaluate(inputSource, resultQName)}}
> * {{doInEvaluateAs}} - {{evaluate(inputSource)}}
> The JDK XPath implementation then creates its own {{DocumentBuilder}} with
> default settings
> ({{com.sun.org.apache.xpath.internal.jaxp.XPathImplUtil.getDocument}}), so
> none of the features above apply on that path: a {{DOCTYPE}} declaration is
> accepted, and an external entity declared in the internal subset is resolved
> and expanded into the evaluated document. Confirmed on JDK 21.0.10.
> {{documentType}} is documented as a way to use SAX streams - a performance
> choice. Neither its name nor its javadoc indicates that it also changes the
> parser configuration, so the two paths should agree on parser hardening.
> Worth noting for the fix: that same {{XPathImplUtil.getDocument}} call means
> {{evaluate(InputSource)}} already builds a full DOM internally. Parsing the
> {{InputSource}} with Camel's hardened {{DocumentBuilder}} first therefore
> does not introduce a document parse that was not already happening - verified
> by evaluating an expression matching the first element of a document that is
> malformed only in its tail, which fails with a {{SAXParseException}} raised
> from {{XPathImplUtil.getDocument}}.
> Present on {{main}}, {{camel-4.22.x}} and {{camel-4.18.x}} - the same four
> call sites exist on all three.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)