Skip to content

Secrets used for ZAP Advanced with authentication are logged to the stdout #1497

Description

@patrykzzz

Your Question

Hi,
When running the ZAP Advanced scan using the example config from here, the loginRequestData is logged to the console by the pod in the Kubernetes cluster.
It means that anyone with access to logs can see the credentials that are used.
Is there a way to change the log level with some configuration to not expose this data?
I saw that here the log level is set to info, but I am not an expert in python.
The log looks like this in the console:

2022-12-09 10:22 ZapConfigureContextAuthentication INFO    : HTTP ZAP HTTP JSON Params: 'loginUrl=http://juice-shop.securecodebox-targets.svc.cluster.local:3000/rest/user/login&loginRequestData={"email":"admin@juice-sh.op","password":"admin123"}'

The code that logs it seems to be

 if "loginUrl" in json_auth:
            auth_method_config_params = "loginUrl=" + json_auth["loginUrl"]
            if "loginRequestData" in json_auth:
                auth_method_config_params += (
                    "&loginRequestData=" + json_auth["loginRequestData"]
                )

            logging.info("HTTP ZAP HTTP JSON Params: '%s'", auth_method_config_params)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugBugsquestionFurther information is requestedscannerImplement or update a security scanner

    Type

    No type

    Projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions