Skip to main content

Management / Logging / Threats / DEV

Log Injection

CCC.Logging.TH06

User-supplied data such as scripts, control characters, escape sequences, or code fragments may be written to logs without proper encoding or sanitization. This can result in malformed or unexpected log entries that could disrupt or compromise systems that process or display these logs, including log viewers or downstream services.

Related Capabilities

IDTitleDescription
CCC.Core.CP10Log PublicationThe service automatically publishes structured, verbose records of activities, operations, or events that occur within the service.
CCC.Logging.CP01Service Log CaptureAbility to capture logs from all relevant cloud services at varying levels of verbosity.
CCC.Logging.CP02Application Log IngestionSupport for ingesting logs from custom applications deployed within the cloud environment.

External Mappings

FrameworkIDRemarks
OWASPTOP10A03:2021
OWASPTOP10A09:2021
CWECWE-79
CWECWE-117
CWECWE-116