SAML authentication bypass through XML comments

Prevent inconsistent XML-comment handling between SAML signature checks and user identification

Description

If XML comments split text and a SAML application reads only part of a value such as NameID, the account selected for login may differ from the value covered by signature validation. A signature can remain valid when its canonicalization excludes comments. This does not mean comments alone make an unsigned assertion trusted.

Potential impact

  • Login as another account in an implementation with vulnerable identity extraction
  • Access to that account's data or functions

Remediation

  1. Use a supported SAML library and verify how it reads identifiers containing comments. Read the complete identifier from the assertion whose signature was validated.
  2. Configure the XML parser actually used for SAML to ignore comments. setIgnoreComments(true) is a supplementary setting, not complete authentication validation.
  3. Validate signatures against trusted IdP keys, together with issuer, audience, recipient, validity times and request correlation required by the flow.

Examples

These excerpts configure the legacy OpenSAML 2 family’s org.opensaml.xml.parse.BasicParserPool. Parser initialization and connection to the actual SAML processor are omitted. Apply the API and security configuration appropriate to the installed version.

Before

java
import org.opensaml.xml.parse.BasicParserPool;

public class InsecureSAMLConfig {
    public void configureParser() {
        BasicParserPool parserPool = new BasicParserPool();
        parserPool.setIgnoreComments(false); // Retain XML comments
    }
}

After

java
import org.opensaml.xml.parse.BasicParserPool;

public class SecureSAMLConfig {
    public void configureParser() {
        BasicParserPool parserPool = new BasicParserPool();
        parserPool.setIgnoreComments(true); // Ignore XML comments; SAML validation is still required
    }
}

The first retains comments; the second ignores them while parsing. This setting does not prevent every form of SAML authentication bypass.

References