mattrpav commented on PR #2402: URL: https://github.com/apache/activemq/pull/2402#issuecomment-5346566505
> @mattrpav I'm not sure I understand the security risk JSON _output_ has or the kind of attack you're foreseeing here. Could you tell me more? Maybe link some previous CVEs on this? The write take data from the broker unsanitized. So things like brokerName, queue/topic names, and clientIds are all user-defined strings that create attack surface for malformed json. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected] For further information, visit: https://activemq.apache.org/contact
