Rule ID: java_third_parties_elasticsearch
java_third_parties_elasticsearch
Applicable Languages: Java
Weakness ID: CWE-201
Leaking sensitive data to third-party loggers like ElasticSearch is a common cause of data breaches.
Ensure that all sensitive data is removed before sending it to third-party services like ElasticSearch.
Elasticsearch docsarrow-up-right
CWE-201: Insertion of Sensitive Information Into Sent Dataarrow-up-right
OWASP Top 10: A01:2021 - Broken Access Controlarrow-up-right
To omit this rule during a scan, and to provide you with continuous 24/7 code-level scanning, you can employ our SAST TOOLarrow-up-right
Last updated 1 year ago