Description
Writing user input to a log without neutralizing line breaks can let an attacker insert forged log entries or confuse log analysis.
Potential impact
- Incident detection and investigation may become more difficult.
- An HTML log viewer may be vulnerable to XSS if it interprets the input as HTML.
Remediation
- Remove
\rand\n, or encode input for the log format before writing it. - Log normalized values or identifiers instead of raw user input.
Examples
Before
go
user := r.FormValue("user")
log.Printf("user=%s", user)
After
go
user := strings.ReplaceAll(r.FormValue("user"), "\n", "")
user = strings.ReplaceAll(user, "\r", "")
log.Printf("user=%s", user)
Explanation:
- Before: Recording input without neutralizing line breaks can let attackers forge log lines. A viewer that interprets unencoded input as HTML introduces an additional risk.
- After: Removing
\rand\nreduces line-based forgery. This does not perform HTML encoding; a web log viewer still needs encoding for its output context.