Description
If XML comments split text and a SAML application reads only part of a value such as NameID, the account selected for login may differ from the value covered by signature validation. A signature can remain valid when its canonicalization excludes comments. This does not mean comments alone make an unsigned assertion trusted.
Potential impact
- Login as another account in an implementation with vulnerable identity extraction
- Access to that account's data or functions
Remediation
- Use a supported SAML library and verify how it reads identifiers containing comments. Read the complete identifier from the assertion whose signature was validated.
- Configure the XML parser actually used for SAML to ignore comments.
setIgnoreComments(true)is a supplementary setting, not complete authentication validation. - Validate signatures against trusted IdP keys, together with issuer, audience, recipient, validity times and request correlation required by the flow.
Examples
These excerpts configure the legacy OpenSAML 2 family’s org.opensaml.xml.parse.BasicParserPool. Parser initialization and connection to the actual SAML processor are omitted. Apply the API and security configuration appropriate to the installed version.
Before
import org.opensaml.xml.parse.BasicParserPool;
public class InsecureSAMLConfig {
public void configureParser() {
BasicParserPool parserPool = new BasicParserPool();
parserPool.setIgnoreComments(false); // Retain XML comments
}
}
After
import org.opensaml.xml.parse.BasicParserPool;
public class SecureSAMLConfig {
public void configureParser() {
BasicParserPool parserPool = new BasicParserPool();
parserPool.setIgnoreComments(true); // Ignore XML comments; SAML validation is still required
}
}
The first retains comments; the second ignores them while parsing. This setting does not prevent every form of SAML authentication bypass.