Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Exclude tracebacks from error responses #6420

Open
hannes-ucsc opened this issue Jul 17, 2024 · 1 comment
Open

Exclude tracebacks from error responses #6420

hannes-ucsc opened this issue Jul 17, 2024 · 1 comment
Assignees
Labels
- [priority] Medium compliance [subject] Information and software security enh [type] New feature or request orange [process] Done by the Azul team POAM 2024

Comments

@hannes-ucsc
Copy link
Member

… and instead only return the request UUID and log the error in CloudWatch.

@hannes-ucsc hannes-ucsc added the orange [process] Done by the Azul team label Jul 17, 2024
@achave11-ucsc achave11-ucsc added compliance [subject] Information and software security enh [type] New feature or request debt [type] A defect incurring continued engineering cost - [priority] Medium and removed debt [type] A defect incurring continued engineering cost labels Jul 17, 2024
@nolunwa-ucsc nolunwa-ucsc self-assigned this Aug 13, 2024
@nolunwa-ucsc
Copy link

This was PT Finding from the 2024 assessment
weakness description:
The server reveals information about the software in a HTTP response, such as local file paths and python exception information.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
- [priority] Medium compliance [subject] Information and software security enh [type] New feature or request orange [process] Done by the Azul team POAM 2024
Projects
None yet
Development

No branches or pull requests

3 participants