You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Log output of the Compass Manager could include sensitive data which enables attackers to infiltrate the application. A code review has to be applied to ensure that no sensitive application data (e.g. tokens, passwords, personal data etc.) will be logged by our software.
AC:
Review the log-output of the Compass Manager and ensure that no sensitive data will be disclosed.
Steps to exploit
Attacker reviews the log output, finds sensitive data and abuses it against us.
Risk assessment
Part of the Threat Modelling workshop from 2023-11-29.
Proposed mitigation
Review any log output of the application to ensure that no sensitive data can be disclosed as part of log messages.
The text was updated successfully, but these errors were encountered:
Description
Log output of the Compass Manager could include sensitive data which enables attackers to infiltrate the application. A code review has to be applied to ensure that no sensitive application data (e.g. tokens, passwords, personal data etc.) will be logged by our software.
AC:
Steps to exploit
Attacker reviews the log output, finds sensitive data and abuses it against us.
Risk assessment
Part of the Threat Modelling workshop from 2023-11-29.
Proposed mitigation
Review any log output of the application to ensure that no sensitive data can be disclosed as part of log messages.
The text was updated successfully, but these errors were encountered: