Description
Including exception messages, stack traces, or inner exception details in client responses can expose internal implementation and environment information.
Potential impact
- Internal paths, types, framework behavior, and input validation failure points can help attackers plan further attacks.
Remediation
Return a generic error message to the client and record detailed exception information only in server logs.
Examples
Before
csharp
return BadRequest(new { error = ex.Message });
After
csharp
logger.LogError(ex, "Request failed");
return BadRequest(new { error = "Request failed" });
Explanation:
- Before: Returning exception messages or stack traces to clients can reveal internal paths, types, and implementation details.
- After: Return a generic error to the client and keep detailed exception information in server-side logs.