raboof commented on PR #4235:
URL: https://github.com/apache/logging-log4j2/pull/4235#issuecomment-5468800578

   > states that MSGID and SD-ID are explicitly developer-controlled structural 
identifiers, so feeding attacker data into them is out of scope
   
   the fact that we don't support untrusted input in those fields doesn't mean 
we necessarily need to forbid ourselves from sanitizing them: sanitizing them 
could be seen as a hardening improvement (reducing the impact when an 
application incorrectly does pass untrusted input to those fields) or a general 
improvement (reducing the chance of regular bugs when users pass data that 
would be misinterpreted here). I don't have a strong opinion if those 
motivations are worth making the change.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to