R364 – Using ‘LOG EVENT’ to trace could leak information (CWE-209: Information Exposure Through an Error Message) (WMB)

Using ‘LOG EVENT’ to trace could leak information (CWE-209: Information Exposure Through an Error Message) ? (WMB)

Logging systems errors can lead to privacy violations (such as customers account numbers), or can lead to leaking of privileged system information (such as passwords).

For example, this could be a privacy issue:

Using 'LOG EVENT' to trace could leak information (CWE-209: Information Exposure Through an Error Message)



A more detailed explanation is available here: https://cwe.mitre.org/data/definitions/209.html/