oscerd commented on code in PR #26896:
URL: https://github.com/apache/camel/pull/26896#discussion_r4121094388


##########
docs/user-manual/modules/ROOT/pages/security-model.adoc:
##########
@@ -923,7 +923,11 @@ be closed as `not a vulnerability`.
   `circuitBreaker`, `resilience4j`, JVM heap limits, and the relevant
   component-level options. Algorithmic-complexity attacks in third-party
   libraries are reported to the upstream project unless Camel exposes the
-  parser in a way that bypasses the library's own limits.
+  parser in a way that bypasses the library's own limits. A resource limit
+  that Camel itself offers, such as `maxDecompressedSize` on the Zip File and
+  Tar File data formats, is defence in depth for a property the framework
+  does not claim: a defect that stops it enforcing its documented value is a
+  bug, fixed as `VALID-HARDENING` rather than published as a CVE.

Review Comment:
   Good catch — done in c596856. Extended the `VALID-HARDENING` row in the 
dispositions table so it matches this entry: its Meaning now also covers "a 
resource limit Camel itself offers for a property it does not claim (such as 
`maxDecompressedSize`) fails to enforce its documented value", and its 
"Licensed by" now cites _Out of scope_ alongside _Known limitations_ and 
_Guidance for component authors and reviewers_. Table and entry now agree.
   
   _Claude Code on behalf of oscerd_



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to