Find sensitive data in log statements
Recipe ID
org.openrewrite.java.security.search.FindSensitiveDataInLogsArtifactorg.openrewrite.recipe:rewrite-java-securityFinds logging statements where arguments include variables, fields, or method calls with names that suggest sensitive data (passwords, tokens, SSNs, credit card numbers, etc.). Logging sensitive data can lead to information disclosure through log files (CWE-532).
Single recipeCWE-532securityProprietary
Usage
This recipe has no required configuration options. You’ll need the Moderne CLI configured before running the command below.
mod run . --recipe org.openrewrite.java.security.search.FindSensitiveDataInLogsIf the recipe isn’t available locally, install it with:
mod config recipes jar install org.openrewrite.recipe:rewrite-java-security:RELEASEOptions
| Name | Type | Description |
|---|---|---|
sensitiveFieldNames | List | Case-insensitive substrings to match against variable, field, and method names in log arguments. Defaults to common sensitive identifiers like password, token, ssn, etc. e.g. password,token,ssn,creditCard |
Data tables
Structured output this recipe can produce.
- Source files that had resultsSource files that were modified by the recipe run.
org.openrewrite.table.SourcesFileResults - Source files that had search resultsSearch results that were found during the recipe run.
org.openrewrite.table.SearchResults - Source files that errored on a recipeThe details of all errors produced by a recipe run.
org.openrewrite.table.SourcesFileErrors - Recipe performanceStatistics used in analyzing the performance of recipes.
org.openrewrite.table.RecipeRunStats