Sensitive data in cleartext logs

Sensitive data in cleartext logs

Description

Writing passwords, tokens, session IDs, API keys or personal information to logs can expose those values through collectors, operations consoles, backups and diagnostic tools. Logs may be shared more broadly than the application database and need separate protection.

Potential impact

  • Exposure of credentials and session tokens
  • Disclosure of personal information
  • Continuing risk from retained logs

Remediation

  1. Do not log sensitive values.
  2. If diagnostics require an identifier, use a fixed redaction marker or a separate tracking ID. A plain hash does not make a secret safe to record.
  3. Control log access, retention and encryption in transit.

Examples

Logger and variable declarations are omitted. The userId in the after example may also be personal information; review whether it needs to be logged and control access and retention.

Before

java
logger.info("password={}", password);
logger.debug("token={}", accessToken);

After

java
logger.info("login attempt for userId={}", userId);
logger.debug("token present={}", accessToken != null);

Explanation:

  • Before: Passwords, tokens, session identifiers and API keys in logs or standard output may allow account compromise or information disclosure to anyone with log access.
  • After: Does not record passwords, tokens, session identifiers or Authorization values.

References