Clear-text logging of sensitive data

Remove or redact sensitive values such as passwords and tokens from logs.

Description

Writing passwords, tokens, session identifiers, or API keys to logs or standard output can let someone with log access compromise accounts or sessions and learn internal configuration. In production, stdout and stderr are often forwarded to log collectors too.

Potential impact

  • People who can read logs may see credentials or session values.
  • Sensitive values may be copied into SIEM systems, backups, or external logging services.
  • Long-term retained data may be difficult to remove during incident response.

Remediation

  • Do not log passwords, tokens, or Authorization header values.
  • When needed, record only fixed redaction text, a hashed tracking ID, or a server-side reference.
  • Remove sensitive fields centrally through a redaction helper or logging filter.
  • Apply the same policy to stdout and stderr as to other production logs.

Examples

Before

python
import logging

def bad_parameterized_token(token):
    logging.info("token=%s", token)

After

python
import logging

def safe_masked_token(token):
    logging.info("token=%s", "[REDACTED]")

Explanation:

  • Before: The token value is written directly to the log.
  • After: A fixed redaction string is logged instead of the token.

References