Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: call out that vulnerabilities in non-default configurations are still vulnerabilities.

It is ASF Policy that we create a CVE advisory for all vulnerabilities in our released artifacts, including "low-severity" ones or issues that only affect non-default (but valid) configurations. The goal of an advisory is to give operators the information they need to make an informed decision about the possible urgency to update.

...