Re: [D] Threat model: how should Thread Context (MDC) keys be classified (trusted structural or untrusted content) ? [logging-log4j2]

ppkarwasz (via GitHub) <[email protected]> Tue, 02 Jun 2026 19:25:25 -0000
Newsgroups gmane.comp.jakarta.log4j.devel
Message-ID <ghd-D_kwDOAKJSSM4AmyP1-b41886c3-65b8-41c9-94eb-05420f803a97@gitbox.apache.org>
GitHub user ppkarwasz added a comment to the discussion: Threat model: how should Thread Context (MDC) keys be classified (trusted structural or untrusted content)?

You would be surprised on how many SIEM systems don't use a structured layout: https://docs.cloud.google.com/logging/docs/agent/ops-agent/third-party

Most of those applications use a derivative of `PatternLayout` and the Ops Agent tries to parse them instead of recommending users to switch to a structured layout.

GitHub link: https://github.com/apache/logging-log4j2/discussions/4132#discussioncomment-17156311

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]