Re: Handling reports from oss-fuzz

2022-11-29 Thread Mark Thomas
On 24/11/2022 09:13, Mark Thomas wrote: Hi all, We currently receive reports from oss-fuzz to the Tomcat security list. There is a relatively high volume of reports with a very high false positive rate. To date, we haven't had any valid security issues reported. Concern has been expressed th

Re: Handling reports from oss-fuzz

2022-11-24 Thread jean-frederic clere
On 11/24/22 10:13, Mark Thomas wrote: Hi all, We currently receive reports from oss-fuzz to the Tomcat security list. There is a relatively high volume of reports with a very high false positive rate. To date, we haven't had any valid security issues reported. Concern has been expressed that

Re: Handling reports from oss-fuzz

2022-11-24 Thread Rémy Maucherat
On Thu, Nov 24, 2022 at 10:14 AM Mark Thomas wrote: > > Hi all, > > We currently receive reports from oss-fuzz to the Tomcat security list. > There is a relatively high volume of reports with a very high false > positive rate. To date, we haven't had any valid security issues reported. > > Concern

Handling reports from oss-fuzz

2022-11-24 Thread Mark Thomas
Hi all, We currently receive reports from oss-fuzz to the Tomcat security list. There is a relatively high volume of reports with a very high false positive rate. To date, we haven't had any valid security issues reported. Concern has been expressed that oss-fuzz is generating excessive noise