Skip to main content

CCC.AUDITLOG.TH04: Insufficient encoding of audit logs

Threat ID:CCC.AUDITLOG.TH04
Title:Insufficient encoding of audit logs
Description:

User-supplied data such as scripts, control characters, escape sequences, or code fragments may be written to audit logs without proper encoding or sanitization. This can result in malformed or unexpected log entries that could disrupt or compromise systems that process or display these logs, including log viewers or downstream services.

Related Capabilities

IDTitleDescription
CCC.AuditLog.F03SinkAbility to continually stream audit log data to a hosted storage bucket or data lake solution.
CCC.AuditLog.F08External SinkAudit log events can be configured to be sent to a external SIEM or data analysis provider outside of the cloud platform.
CCC.Core.F03Access Log PublicationThe service automatically publishes structured, verbose records of activities performed within the scope of the service by external actors.
CCC.Core.F10Log PublicationThe service automatically publishes structured, verbose records of activities, operations, or events that occur within the service.

External Mappings

Reference IDEntry IDStrengthRemarks
OWASPTOP10
A03:2021
0
-
OWASPTOP10
A09:2021
0
-
CWE
CWE-79
0
-
CWE
CWE-117
0
-
CWE
CWE-116
0
-