Hacker News new | past | comments | ask | show | jobs | submit login

https://cwe.mitre.org/data/definitions/117.html

'CWE-117: Improper Output Neutralization for Logs'

That is something probably often forgotten when simply dumping some requests into a log, but at least it should be obvious that the source of the content is untrusted. On the other hand, a log file is a file on your server, so you would probably think of it as nothing dangerous, as everybody has cared about CWE-117, right? ;-)




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: