Ignore SAML comments

Metadata

ID: java-security/ignore-saml-comment

Language: Java

Severity: Error

Category: Security

Description

Ignoring comments in SAML may lead to vulnerabilities.

Learn More

Non-Compliant Code Examples

public class MyClass {
 
    @Bean
    ParserPool myParserPool() {
        BasicParserPool pool = new BasicParserPool();
        pool.setIgnoreComments(false);
        return pool;
    }
}

Compliant Code Examples

public class MyClass {
 
    @Bean
    ParserPool myParserPool() {
        BasicParserPool pool = new BasicParserPool();
        return pool;
    }
}