Well, as long as the xml isn't under the root of the web site and browsable, the major security concern is someone getting access to the web server itself. Absent that, isn't hurt. Lots of apps store secure info in the web.config.
Ideally, that information would be stored in an encrypted fashion and the dlls for the .net app obfuscated. But, that rarely happens with web apps.