raboof commented on PR #4235: URL: https://github.com/apache/logging-log4j2/pull/4235#issuecomment-5468800578
> states that MSGID and SD-ID are explicitly developer-controlled structural identifiers, so feeding attacker data into them is out of scope the fact that we don't support untrusted input in those fields doesn't mean we necessarily need to forbid ourselves from sanitizing them: sanitizing them could be seen as a hardening improvement (reducing the impact when an application incorrectly does pass untrusted input to those fields) or a general improvement (reducing the chance of regular bugs when users pass data that would be misinterpreted here). I don't have a strong opinion if those motivations are worth making the change. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
