# Generation of Error Message Containing Sensitive Information (CWE-209) The product generates an error message that includes sensitive information about its environment, users, or associated data. **Stack:** Go - Prevalence: Média 3 linguagens cobertas - Impact: Médio Revisão recomendada - Prevention: Documentada 5 exemplos de correção **OWASP:** Insecure Design (A04:2021-Insecure Design) - #4 ## Description The sensitive information may be valuable information on its own, or it may be useful for launching other, more serious attacks. The error message may be created in different ways, and the information that is included can range widely. ## Prevention Estratégias de prevenção para Error Message Information Leak baseadas em 1 regras de detecção do Shoulder. ### Go Return generic error messages to clients; log detailed errors server-side ## Consequences - Ler dados da aplicação - Ler arquivos ou diretórios ## Mitigations - Trate exceções internamente e não exiba erros para o usuário - Crie páginas de erro padrão para erros HTTP como 404 e 500 - Implemente um tratamento de erros que registre detalhes no servidor mas mostre mensagens genéricas aos usuários ## Detection - Total rules: 5 - Languages: go, javascript, typescript, python ## Rules by Language ### Go (1 rules) - **Database Error Information Exposure in HTTP Response** [MEDIUM]: Internal error messages or stack traces exposed to users in HTTP responses. - Remediation: Return generic error messages to users, log details server-side. ```go if err != nil { log.Printf("internal error: %v", err) // Log details http.Error(w, "An error occurred", 500) // Generic response return } ``` Learn more: https://shoulder.dev/learn/go/cwe-209/error-message-exposure