测试版 Shoulder 目前处于测试阶段 — 结果有时可能不正确。您的反馈塑造我们接下来要修复的内容。 分享反馈
⚠️

Generation of Error Message Containing Sensitive Information

🛡️ 5 条规则检测到此问题

Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

The sensitive information may be valuable information on its own, or it may be useful for launching other, more serious attacks. The error message may be created in different ways, and the information that is included can range widely.

普遍性
覆盖 3 种语言
影响
建议审查
预防
已记录
5 个修复示例
2 预防
2 预防

如何修复此漏洞

基于 5 条 Shoulder 检测规则的 Error Message Information Leak 预防策略。

Database Error Information Exposure in HTTP Response MEDIUM

Return generic error messages to clients; log detailed errors server-side

+2 -1 go
  func handler(w http.ResponseWriter, r *http.Request) {
      rows, err := db.Query("SELECT * FROM users")
      if err != nil {
-         http.Error(w, err.Error(), 500)
+         log.Printf("database query failed: %v", err)
+         http.Error(w, "Internal server error", 500)
          return
      }
  }
  
Information Exposure Through Error Messages MEDIUM

Return generic error messages to users and log detailed errors server-side

+2 -1 javascript
  } catch (error) {
-   res.status(500).json({ error: error.message, stack: error.stack });
+   logger.error('Operation failed', { error: error.message });
+   res.status(500).json({ error: 'An error occurred' });
  }
  
tRPC Error Information Disclosure MEDIUM

Configure errorFormatter to strip stack traces in production and use TRPCError with generic messages

+26 -14 javascript
- import { initTRPC } from '@trpc/server';
- import { router, publicProcedure } from './trpc';
- 
- export const t = initTRPC.context<Context>().create({
-   // No errorFormatter configured
- });
- 
- export const userRouter = router({
-   createUser: publicProcedure
-     .mutation(async ({ input }) => {
-       try {
-         return await db.user.create({ data: input });
-       } catch (err) {
-         throw err; // Raw database error exposed to client
+ import { initTRPC, TRPCError } from '@trpc/server';
+ 
+ export const t = initTRPC.context<Context>().create({
+   errorFormatter({ shape }) {
+     return {
+       ...shape,
+       data: {
+         ...shape.data,
+         stack: process.env.NODE_ENV === 'production'
+           ? undefined
+           : shape.data.stack,
+       },
+     };
+   },
+ });
+ 
+ export const userRouter = router({
+   createUser: publicProcedure
+     .mutation(async ({ input }) => {
+       try {
+         return await db.user.create({ data: input });
+       } catch (err) {
+         throw new TRPCError({
+           code: 'INTERNAL_SERVER_ERROR',
+           message: 'Failed to create user',
+         });
        }
      })
  });
  
Error Message Information Disclosure MEDIUM

Log full exception details internally but return generic error messages to users

+13 -9 python
- from flask import jsonify
- 
- @app.route('/api/process')
- def process():
-     try:
-         result = expensive_operation()
-         return jsonify(result)
-     except Exception as e:
-         return jsonify({'error': str(e)}), 500
+ import logging
+ from flask import jsonify
+ 
+ logger = logging.getLogger(__name__)
+ 
+ @app.route('/api/process')
+ def process():
+     try:
+         result = expensive_operation()
+         return jsonify(result)
+     except Exception as e:
+         logger.error(f"Processing failed: {e}", exc_info=True)
+         return jsonify({'error': 'Internal server error'}), 500
  
Internal Path and IP Address Disclosure MEDIUM

Return generic responses; log internal paths server-side only

+9 -9 python
- from flask import jsonify
- 
- @app.route('/info')
- def get_info():
-     return jsonify({
-         'status': 'ok',
-         'path': __file__,
-         'cwd': os.getcwd()
-     })
+ import logging
+ from flask import jsonify
+ 
+ logger = logging.getLogger(__name__)
+ 
+ @app.route('/info')
+ def get_info():
+     logger.info(f"Info request from {__file__}")
+     return jsonify({'status': 'ok', 'version': '1.0'})
  
3 检测
3 检测

查找代码中的漏洞

使用Shoulder扫描代码中的Generation of Error Message Containing Sensitive Information模式。 5 规则.

终端
# Scan with Shoulder CLI
npx @shoulderdev/cli trust --cwe=209

# Or scan entire project
npx @shoulderdev/cli trust .

检测规则 (5)

4 警告信号
4 警告信号

代码审查中需要关注的内容

这些模式表明潜在的Generation of Error Message Containing Sensitive Information漏洞。在代码审查和安全审计中注意查找。

🟡
exposure of sensitive error information (error javascript-error-message-exposure
🟡
error messages that expose sensitive implementation details like stack traces, database errors, file python-error-message-exposure
🟡
responses that include internal file paths, IP addresses, or system information python-internal-path-disclosure
🟡
Error handling exposes implementation details. Use error formatter to sanitize errors in production. trpc-error-information-leak
🔍

扫描你的代码库: Generation of Error Message Containing Sensitive Information

Shoulder CLI 在整个代码库中找到易受攻击的模式。