CWE一覧に戻る
CWE-532

ログファイルへの機密情報の挿入

Insertion of Sensitive Information into Log File
脆弱性 作成中
JA

この製品は、機密情報をログファイルに書き込みます。

EN

The product writes sensitive information to a log file.

Scope: Confidentiality / Impact: Read Application Data
Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files.
Remove debug log files before deploying the application into production.
Protect log files against unauthorized read/write.
Adjust configurations appropriately when software is transitioned from a debug state to production.
MITRE公式ページ — CWE-532