# Insertion of Sensitive Information into Log File (CWE-532) Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. **Stack:** Go - Prevalence: Média 3 linguagens cobertas - Impact: Alto 1 regras de severidade alta - Prevention: Documentada 3 exemplos de correção **OWASP:** Security Logging and Monitoring Failures (A09:2021-Security Logging and Monitoring Failures) - #9 ## Description When sensitive information like passwords, tokens, or personal data is logged, it becomes accessible to anyone with access to the logs. Log files are often stored with less security than the data they contain. ## Prevention Estratégias de prevenção para Information Exposure Through Logs baseadas em 1 regras de detecção do Shoulder. ### Go Never log passwords, tokens, or PII; log presence/absence instead ## Consequences - Ler dados da aplicação - Obter privilégios ## Mitigations - Nunca registre em log informações sensíveis como senhas ou tokens - Implemente classificação e filtragem dos dados de log - Mascare ou redija dados sensíveis antes de registrar em log ## Detection - Total rules: 3 - Languages: go, javascript, typescript, python ## Rules by Language ### Go (1 rules) - **Logging Sensitive Data** [MEDIUM]: Passwords, tokens, or PII logged via log.Printf or similar functions. - Remediation: Never log sensitive values. Log presence/absence instead of actual values. ```go // Log only that API key is configured, not the value if apiKey != "" { log.Println("API key configured") } ``` Learn more: https://shoulder.dev/learn/go/cwe-532/sensitive-data-logging