← All recipes
Moderne licensed

Find sensitive data in log statements

Recipe IDorg.openrewrite.java.security.search.FindSensitiveDataInLogsArtifactorg.openrewrite.recipe:rewrite-java-security

Finds logging statements where arguments include variables, fields, or method calls with names that suggest sensitive data (passwords, tokens, SSNs, credit card numbers, etc.). Logging sensitive data can lead to information disclosure through log files (CWE-532).

Single recipeCWE-532securityProprietary

Usage

This recipe has no required configuration options. You’ll need the Moderne CLI configured before running the command below.

mod run . --recipe org.openrewrite.java.security.search.FindSensitiveDataInLogs

If the recipe isn’t available locally, install it with:

mod config recipes jar install org.openrewrite.recipe:rewrite-java-security:RELEASE

Options

NameTypeDescription
sensitiveFieldNamesListCase-insensitive substrings to match against variable, field, and method names in log arguments. Defaults to common sensitive identifiers like password, token, ssn, etc.
e.g. password,token,ssn,creditCard

Data tables

Structured output this recipe can produce.

  • Source files that had resultsSource files that were modified by the recipe run.org.openrewrite.table.SourcesFileResults
  • Source files that had search resultsSearch results that were found during the recipe run.org.openrewrite.table.SearchResults
  • Source files that errored on a recipeThe details of all errors produced by a recipe run.org.openrewrite.table.SourcesFileErrors
  • Recipe performanceStatistics used in analyzing the performance of recipes.org.openrewrite.table.RecipeRunStats