This is an automated email from the ASF dual-hosted git repository.
jungm pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomee.git
The following commit(s) were added to refs/heads/main by this push:
new 758d6cdc8e update SECURITY.md with feedback from ASF Security team
758d6cdc8e is described below
commit 758d6cdc8e0e6912033463cdfc5dc123fc6b1b13
Author: Markus Jung <[email protected]>
AuthorDate: Wed Jun 3 10:40:45 2026 +0200
update SECURITY.md with feedback from ASF Security team
---
SECURITY.md | 21 +++++++++++++++++++++
1 file changed, 21 insertions(+)
diff --git a/SECURITY.md b/SECURITY.md
index 6cb48ec3a4..e7b95dd6dc 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -4,6 +4,24 @@ Apache TomEE is a Jakarta EE and MicroProfile runtime. The
Apache TomEE Security
Report suspected vulnerabilities privately to **[email protected]**. Do not
file security reports as public Jira tickets or GitHub issues.
+## Triage dispositions
+
+Every report resolves to exactly one of four dispositions. A triager applies
the disposition and cites the section below that licenses it.
+
+- **VALID** — a vulnerability in TomEE's own attack surface (see *In scope*
below). Accepted and fixed.
+- **BY-DESIGN** — the behaviour is an intentional property of a protocol or
feature, not a defect (e.g. EJBd Java-object deserialization; see *Connectors
and transports*).
+- **OUT-OF-MODEL** — a real or hypothetical issue that falls outside the trust
boundaries of this model. Cite the controlling section: a trusted actor
(*Administrative users*, *Deployed applications*), the trusted-network
deployment contract (*Connectors and transports*, *Embedded network services*,
*Service discovery*), a flaw in a bundled library as released (*Bundled
third-party libraries*), or generic resource exhaustion / DoS (*Connectors and
transports*).
+- **KNOWN-NON-FINDING** — the report matches an entry in *Known non-findings*.
Pre-adjudicated; repeated submissions are treated as spam. This label takes
precedence: if a report matches the Known non-findings list, label it here
rather than by its underlying reason.
+
+### In scope — what IS a TomEE vulnerability
+
+These are the active search targets. A finding in any of them is VALID:
+
+- **Bundled-webapp endpoints** — the TomEE web applications shipped in ASF
distributions (the TomEE webapp, web console, REST admin endpoints,
`webaccess`, plus/plume admin UIs), including CSRF that tricks an administrator
(see *Administrative users*, *Deployed applications*).
+- **TomEE integration code** — the wiring that exposes bundled libraries
through TomEE's deployment model, configuration, and defaults (see *Bundled
third-party libraries*).
+- **TomEE-modified library code** — anything TomEE forks, patches,
shades/relocates, or bytecode-transforms at build time, even when it sits in an
upstream package namespace (see *Bundled third-party libraries*).
+- **Amplification resource exhaustion** — a single bounded, well-formed
request that causes disproportionate (super-linear or unbounded) resource
consumption because of a defect in TomEE-owned code, on a connector that does
not require a trusted network (see *Connectors and transports*).
+
## Administrative users
Administrative users are always considered to be trusted. Reports for
vulnerabilities where an attacker already has access to or control over any of
the following will be rejected:
@@ -50,6 +68,8 @@ Data received via any TomEE-exposed connector or transport is
considered to be u
All clients — including reverse proxies and remote EJB clients using
`openejb-client` — are responsible for the consequences of the data they
present to TomEE. If a client presents a malformed request that TomEE processes
per the protocol specification, any security impact to the client is the
client's responsibility.
+**Resource exhaustion and denial of service.** Generic DoS is out of scope:
request or connection floods, slow-client (Slowloris-style) attacks,
large-but-linear payloads, and resource cost inherent to a protocol or to a
bundled library as released are not treated as TomEE vulnerabilities. The
exception is amplification — a single bounded, well-formed request that
triggers disproportionate (super-linear or unbounded) CPU, memory, or thread
consumption because of a defect in TomEE-owned c [...]
+
## Embedded network services
TomEE can be configured to start network-listening services beyond the main
HTTP and EJBd transports. Each is admin-enabled; when enabled, the following
services require a trusted network or explicit authentication, and exposing
them on an untrusted network without hardening is misuse, not a TomEE
vulnerability:
@@ -116,3 +136,4 @@ The following non-findings are frequently reported despite
being invalid under t
3. Any report that depends on deploying a malicious application — deployed
applications are trusted (see *Deployed applications*).
4. Any report against the EJBd protocol, JMX, the embedded ActiveMQ broker,
Derby Network Server, HSQLDB Server, or other management or admin endpoints
that assumes they should be safe to expose on an untrusted network without
authentication (see *Connectors and transports* and *Embedded network
services*).
5. Any report against bundled third-party libraries — including but not
limited to CXF, ActiveMQ, MyFaces, Mojarra, OpenJPA, BVal, HSQLDB, Derby, and
MicroProfile implementations — where the root cause is in the upstream library
as released rather than in TomEE's integration code or in any code TomEE forks,
patches, shades, or byte-code-transforms (see *Bundled third-party libraries*).
+6. Any report of generic denial of service — request or connection floods,
slow-client attacks, large-but-linear payloads, or resource cost inherent to a
protocol or bundled library — absent a specific amplification defect in
TomEE-owned code (see *Resource exhaustion and denial of service* under
*Connectors and transports*).