|
|
|
|
CWE-542: Information Exposure Through Cleanup Log Files
| | Information Exposure Through Cleanup Log Files |
|
| Weakness ID: 542 (Weakness Variant) | | Status: Incomplete |
Description
Description Summary The application does not properly protect or delete a log file related to cleanup.
Time of Introduction
- Architecture and Design
- Implementation
Common Consequences | Scope | Effect |
Confidentiality | Technical Impact: Read application
data |
Potential Mitigations
Do not store sensitive information in log files. |
Relationships Taxonomy Mappings | Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
| Anonymous Tool Vendor (under NDA) | | | |
| CERT Java Secure Coding | FIO08-J | | Do not log sensitive information outside a trust
boundary |
Content History | Submissions |
|---|
| Submission Date | Submitter | Organization | Source |
|---|
| Anonymous Tool Vendor (under NDA) | | Externally Mined | | | Modifications |
|---|
| Modification Date | Modifier | Organization | Source |
|---|
| 2008-07-01 | Eric Dalci | Cigital | External | | updated Potential_Mitigations,
Time_of_Introduction | | 2008-09-08 | CWE Content Team | MITRE | Internal | | updated Relationships,
Taxonomy_Mappings | | 2009-03-10 | CWE Content Team | MITRE | Internal | | updated Relationships | | 2011-03-29 | CWE Content Team | MITRE | Internal | | updated Description, Name | | 2011-06-01 | CWE Content Team | MITRE | Internal | | updated Common_Consequences, Relationships,
Taxonomy_Mappings | | Previous Entry Names |
|---|
| Change Date | Previous Entry
Name |
|---|
| 2011-03-29 | Information Leak Through
Cleanup Log Files | |
|