Description
Writing passwords, tokens or session values to logs or standard output in plaintext may let someone with log access take over an account.
Potential impact
- Sensitive information may be exposed through log collectors, consoles or incident reports.
- Long-retained logs may enable session or account takeover.
Remediation
- Do not log sensitive values.
- Where needed, apply masking or redaction, including protection of individual structured-log fields.
Examples
Before
go
log.Printf("password=%s", password)
After
go
log.Printf("password=<redacted>")
Explanation:
- Before: Plaintext passwords, tokens or session values in logs may enable account or session takeover by someone with log access.
- After: Sensitive values such as passwords, tokens, session identifiers and Authorization headers are not recorded.