davsclaus commented on code in PR #26896:
URL: https://github.com/apache/camel/pull/26896#discussion_r4112510443
##########
docs/user-manual/modules/ROOT/pages/security-model.adoc:
##########
@@ -923,7 +923,11 @@ be closed as `not a vulnerability`.
`circuitBreaker`, `resilience4j`, JVM heap limits, and the relevant
component-level options. Algorithmic-complexity attacks in third-party
libraries are reported to the upstream project unless Camel exposes the
- parser in a way that bypasses the library's own limits.
+ parser in a way that bypasses the library's own limits. A resource limit
+ that Camel itself offers, such as `maxDecompressedSize` on the Zip File and
+ Tar File data formats, is defence in depth for a property the framework
+ does not claim: a defect that stops it enforcing its documented value is a
+ bug, fixed as `VALID-HARDENING` rather than published as a CVE.
Review Comment:
This sends such findings to `VALID-HARDENING`, but that row in the
dispositions table ("Licensed by": _Known limitations_, _Guidance for component
authors and reviewers_) doesn't cite _Out of scope_, and its Meaning only
covers "a recurring misuse or scanner pattern". Could you extend that row so
the table and this entry agree?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]