Your Question
Hi,
When running the ZAP Advanced scan using the example config from here, the loginRequestData is logged to the console by the pod in the Kubernetes cluster.
It means that anyone with access to logs can see the credentials that are used.
Is there a way to change the log level with some configuration to not expose this data?
I saw that here the log level is set to info, but I am not an expert in python.
The log looks like this in the console:
2022-12-09 10:22 ZapConfigureContextAuthentication INFO : HTTP ZAP HTTP JSON Params: 'loginUrl=http://juice-shop.securecodebox-targets.svc.cluster.local:3000/rest/user/login&loginRequestData={"email":"admin@juice-sh.op","password":"admin123"}'
The code that logs it seems to be
if "loginUrl" in json_auth:
auth_method_config_params = "loginUrl=" + json_auth["loginUrl"]
if "loginRequestData" in json_auth:
auth_method_config_params += (
"&loginRequestData=" + json_auth["loginRequestData"]
)
logging.info("HTTP ZAP HTTP JSON Params: '%s'", auth_method_config_params)
Your Question
Hi,
When running the ZAP Advanced scan using the example config from here, the loginRequestData is logged to the console by the pod in the Kubernetes cluster.
It means that anyone with access to logs can see the credentials that are used.
Is there a way to change the log level with some configuration to not expose this data?
I saw that here the log level is set to info, but I am not an expert in python.
The log looks like this in the console:
The code that logs it seems to be