ppkarwasz opened a new issue, #4331:
URL: https://github.com/apache/logging-log4j2/issues/4331

   When `NoSqlAppender` is configured with a layout that returns a 
`MapMessage`, `NoSqlDatabaseManager#setFields(MapMessage, NoSqlObject)` copies 
every entry of the message into the top-level document without checking the 
key. With the CouchDB provider a key named `_id` is honored as the document 
identifier, and an `_id` starting with `_design/` creates or overwrites a 
design document. Other providers have their own reserved names (`_id` for 
MongoDB).
   
   `MapMessage` keys are developer-controlled structural identifiers under the 
[threat 
model](https://logging.apache.org/security.html#threat-common-sources-structural),
 so this is not a vulnerability, but the model allows us to reject a malformed 
identifier rather than silently accept it. This issue originates from a private 
security report classified as not a vulnerability.
   
   Proposal: let `NoSqlProvider` (or `NoSqlConnection`) expose the set of 
reserved field names, and have `NoSqlDatabaseManager` skip or prefix colliding 
keys, logging a status warning the first time. Note that `log4j-couchdb` is 
planned for removal, so the CouchDB-specific part may be moot.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to