Exception information exposure

Exception information exposure in C#

Description

Including exception messages, stack traces, or inner exception details in client responses can expose internal implementation and environment information.

Potential impact

  • Internal paths, types, framework behavior, and input validation failure points can help attackers plan further attacks.

Remediation

Return a generic error message to the client and record detailed exception information only in server logs.

Examples

Before

csharp
return BadRequest(new { error = ex.Message });

After

csharp
logger.LogError(ex, "Request failed");
return BadRequest(new { error = "Request failed" });

Explanation:

  • Before: Returning exception messages or stack traces to clients can reveal internal paths, types, and implementation details.
  • After: Return a generic error to the client and keep detailed exception information in server-side logs.

References