Skip to main content

CCC.Logging.TH06: Log Injection

Threat ID:CCC.Logging.TH06
Title:Log Injection
Description:

User-supplied data such as scripts, control characters, escape sequences, or code fragments may be written to logs without proper encoding or sanitization. This can result in malformed or unexpected log entries that could disrupt or compromise systems that process or display these logs, including log viewers or downstream services.

External Mappings

Reference IDEntry IDStrengthRemarks
OWASPTOP10
A03:2021
0
-
OWASPTOP10
A09:2021
0
-
CWE
CWE-79
0
-
CWE
CWE-117
0
-
CWE
CWE-116
0
-