> For the complete documentation index, see [llms.txt](https://docs.sec1.io/user-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sec1.io/user-docs/4-sast/3-javascript/leakage-of-sensitive-information-in-logger-message.md).

# Leakage of sensitive information in logger message

## Overview

* **Rule ID**: `javascript_lang_logger`
* **Applicable Languages**: Javascript
* **Weakness ID**: CWE-532

## Description

Sensitive information leakage through log messages can compromise user privacy and security. This vulnerability arises when log messages include sensitive data, such as personally identifiable information (PII), making it accessible to unauthorized individuals.

## Remediation Guidelines

* **Avoid including sensitive data in log messages.** This can result in unintended exposure of private information.

  ```javascript
  logger.info(`User is: ${user.email}`); // unsafe


  ```
* **Use non-sensitive**, unique identifiers to reference users in log messages. This approach maintains user privacy while still allowing for effective logging.

  ```javascript
  logger.info(`User is: ${user.uuid}`)
  ```

## References

* [**OWASP Logging Cheat Sheet**](https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html)
* [**CWE-532: Insertion of Sensitive Information into Log File**](https://cwe.mitre.org/data/definitions/532.html)
* [**OWASP Top 10: A09:2021 - Security Logging and Monitoring Failures**](https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/)

## Configuration

To omit this rule during a scan, and to provide you with continuous 24/7 code-level scanning, you can employ our [**SAST TOOL**](https://scopy.sec1.io/login)
