OpenSAML-Java susceptible to comment attack?
Marc Boorshtein
mboorshtein at gmail.com
Tue Feb 27 23:02:32 EST 2018
>
>
> It does not. At least, not if you are using our ParserPool impl with
> default settings. We completely strip out the comments when we parse the
> input into the DOM. So there's never any comments in the DOM.
>
>
Hmm, looks like I'm using the raw javax.xml.parsers.DocumentBuilder and the
comment issue is not handled properly. Can you point me to some example
code? Looking at the Api docs all I see is GlobalParserPoolInitalizer but
I don't see any actual parsers.
Thanks
Marc
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20180228/70b90585/attachment.html>
More information about the dev
mailing list