This is an automated email from the ASF dual-hosted git repository.

jungm pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomee.git


The following commit(s) were added to refs/heads/main by this push:
     new 758d6cdc8e update SECURITY.md with feedback from ASF Security team
758d6cdc8e is described below

commit 758d6cdc8e0e6912033463cdfc5dc123fc6b1b13
Author: Markus Jung <[email protected]>
AuthorDate: Wed Jun 3 10:40:45 2026 +0200

    update SECURITY.md with feedback from ASF Security team
---
 SECURITY.md | 21 +++++++++++++++++++++
 1 file changed, 21 insertions(+)

diff --git a/SECURITY.md b/SECURITY.md
index 6cb48ec3a4..e7b95dd6dc 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -4,6 +4,24 @@ Apache TomEE is a Jakarta EE and MicroProfile runtime. The 
Apache TomEE Security
 
 Report suspected vulnerabilities privately to **[email protected]**. Do not 
file security reports as public Jira tickets or GitHub issues.
 
+## Triage dispositions
+
+Every report resolves to exactly one of four dispositions. A triager applies 
the disposition and cites the section below that licenses it.
+
+- **VALID** — a vulnerability in TomEE's own attack surface (see *In scope* 
below). Accepted and fixed.
+- **BY-DESIGN** — the behaviour is an intentional property of a protocol or 
feature, not a defect (e.g. EJBd Java-object deserialization; see *Connectors 
and transports*).
+- **OUT-OF-MODEL** — a real or hypothetical issue that falls outside the trust 
boundaries of this model. Cite the controlling section: a trusted actor 
(*Administrative users*, *Deployed applications*), the trusted-network 
deployment contract (*Connectors and transports*, *Embedded network services*, 
*Service discovery*), a flaw in a bundled library as released (*Bundled 
third-party libraries*), or generic resource exhaustion / DoS (*Connectors and 
transports*).
+- **KNOWN-NON-FINDING** — the report matches an entry in *Known non-findings*. 
Pre-adjudicated; repeated submissions are treated as spam. This label takes 
precedence: if a report matches the Known non-findings list, label it here 
rather than by its underlying reason.
+
+### In scope — what IS a TomEE vulnerability
+
+These are the active search targets. A finding in any of them is VALID:
+
+- **Bundled-webapp endpoints** — the TomEE web applications shipped in ASF 
distributions (the TomEE webapp, web console, REST admin endpoints, 
`webaccess`, plus/plume admin UIs), including CSRF that tricks an administrator 
(see *Administrative users*, *Deployed applications*).
+- **TomEE integration code** — the wiring that exposes bundled libraries 
through TomEE's deployment model, configuration, and defaults (see *Bundled 
third-party libraries*).
+- **TomEE-modified library code** — anything TomEE forks, patches, 
shades/relocates, or bytecode-transforms at build time, even when it sits in an 
upstream package namespace (see *Bundled third-party libraries*).
+- **Amplification resource exhaustion** — a single bounded, well-formed 
request that causes disproportionate (super-linear or unbounded) resource 
consumption because of a defect in TomEE-owned code, on a connector that does 
not require a trusted network (see *Connectors and transports*).
+
 ## Administrative users
 
 Administrative users are always considered to be trusted. Reports for 
vulnerabilities where an attacker already has access to or control over any of 
the following will be rejected:
@@ -50,6 +68,8 @@ Data received via any TomEE-exposed connector or transport is 
considered to be u
 
 All clients — including reverse proxies and remote EJB clients using 
`openejb-client` — are responsible for the consequences of the data they 
present to TomEE. If a client presents a malformed request that TomEE processes 
per the protocol specification, any security impact to the client is the 
client's responsibility.
 
+**Resource exhaustion and denial of service.** Generic DoS is out of scope: 
request or connection floods, slow-client (Slowloris-style) attacks, 
large-but-linear payloads, and resource cost inherent to a protocol or to a 
bundled library as released are not treated as TomEE vulnerabilities. The 
exception is amplification — a single bounded, well-formed request that 
triggers disproportionate (super-linear or unbounded) CPU, memory, or thread 
consumption because of a defect in TomEE-owned c [...]
+
 ## Embedded network services
 
 TomEE can be configured to start network-listening services beyond the main 
HTTP and EJBd transports. Each is admin-enabled; when enabled, the following 
services require a trusted network or explicit authentication, and exposing 
them on an untrusted network without hardening is misuse, not a TomEE 
vulnerability:
@@ -116,3 +136,4 @@ The following non-findings are frequently reported despite 
being invalid under t
 3. Any report that depends on deploying a malicious application — deployed 
applications are trusted (see *Deployed applications*).
 4. Any report against the EJBd protocol, JMX, the embedded ActiveMQ broker, 
Derby Network Server, HSQLDB Server, or other management or admin endpoints 
that assumes they should be safe to expose on an untrusted network without 
authentication (see *Connectors and transports* and *Embedded network 
services*).
 5. Any report against bundled third-party libraries — including but not 
limited to CXF, ActiveMQ, MyFaces, Mojarra, OpenJPA, BVal, HSQLDB, Derby, and 
MicroProfile implementations — where the root cause is in the upstream library 
as released rather than in TomEE's integration code or in any code TomEE forks, 
patches, shades, or byte-code-transforms (see *Bundled third-party libraries*).
+6. Any report of generic denial of service — request or connection floods, 
slow-client attacks, large-but-linear payloads, or resource cost inherent to a 
protocol or bundled library — absent a specific amplification defect in 
TomEE-owned code (see *Resource exhaustion and denial of service* under 
*Connectors and transports*).

Reply via email to