JQian990334 (Community Member) asked a question.

CWE 117: Does updating logback configuration to strip out CRLF characters fix this vulnerability?

Our team updated our logback configuration file to replace any instances of CRLF characters in our log statements with an empty string. This should apply globally to all the log statements in our application, but when we performed another Veracode scan, this vulnerability still appeared on the report . Is this not a complete/effective strategy to defend against this vulnerability?

 

Thanks for any insight.


  • Hi @JQian990334 (Community Member)​ ,

     

    Configuring your logging library such that the CR and LF characters are removed or replaced is a good control to introduce to prevent risk from CWE 117, however it is not one that Veracode Static Analysis currently is able to automatically recognize.

     

    Veracode Static Analysis will only automatically recognize removing the external (tainted) data from the log message or use of one of the supported cleansing functions for this category ( https://help.veracode.com/reader/4EKhlLSMHm5jC8P8j3XccQ/IiF_rOE79ANbwnZwreSPGA ) for every log message with external (tainted) data.

     

    Other valid controls must be proposed in a mitigation proposal ( https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/~p4MSKOS8F8X8h0KwFTKoQ ) you must then reach out to a member of your security team to ask them tor review the proposal.

     

    Please let me know if you have any remaining questions or concerns.

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.