OpenSAML-Java susceptible to comment attack?

Marc Boorshtein mboorshtein at gmail.com
Tue Feb 27 23:02:32 EST 2018


>
>
> It does not. At least, not if you are using our ParserPool impl with
> default settings.   We completely strip out the comments when we parse the
> input into the DOM.  So there's never any comments in the DOM.
>
>
Hmm, looks like I'm using the raw javax.xml.parsers.DocumentBuilder and the
comment issue is not handled properly.  Can you point me to some example
code?  Looking at the Api docs all I see is GlobalParserPoolInitalizer but
I don't see any actual parsers.

Thanks
Marc
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20180228/70b90585/attachment.html>


More information about the dev mailing list