Description
Writing a runtime stack trace or panic dump directly to an HTTP response can expose internal package structure, file paths and runtime context.
Potential impact
- Attackers may use internal structure information to refine further attacks.
- Some runtime values or paths may reveal sensitive information.
Remediation
- Write detailed stack traces only to protected server logs and remove sensitive values.
- Return only generic error messages to users.
- Restrict log access and retention.
Examples
Before
go
w.Write(debug.Stack())
After
go
log.Print(string(debug.Stack()))
http.Error(w, "internal server error", http.StatusInternalServerError)
Explanation:
- Before: The HTTP response exposes stack traces or panic dumps, potentially revealing packages, paths, framework structure and sensitive runtime context.
- After: Detailed traces go only to server logs, while the client receives a generic error message.