Description
Logging passwords, tokens, API keys or session identifiers can expose secrets through log collectors and operational dashboards.
Potential impact
- Account takeover, session hijacking or disclosure of keys for external services.
Remediation
Do not log sensitive values. If a record is needed, use a fixed redaction marker or a non-sensitive correlation identifier.
Examples
Before
csharp
logger.LogInformation("Password {Password}", account.Password);
After
csharp
logger.LogInformation("Password [redacted]");
The first example exposes the password through log storage and monitoring systems. The revised example records a fixed marker without the secret value.