logo

Database

Java Slf4j Logger Injection

Description

This detector identifies Java code that writes Spring request data to SLF4J, Log4j2 or Lombok loggers without neutralizing line breaks. An attacker who controls that data can insert carriage returns and line feeds to forge log entries, hide malicious activity or mislead the systems that process the logs.

Weakness:

091 - Log injection

Category: System Manipulation

Detection Strategy

    • The code must import org.slf4j, org.apache.logging.log4j or lombok.extern

    • A logging method call (such as info, debug, warn or error) must be made on a logger created with LoggerFactory.getLogger or LogManager.getLogger, or on the log field generated by Lombok @Slf4j or @Log4j2

    • At least one argument of the logging call must carry text that a client controls: a parameter annotated with @RequestParam, @PathVariable, @RequestHeader, @RequestBody, @RequestPart, @ModelAttribute or @CookieValue, or the original file name or part name of a MultipartFile

    • The value can reach the call directly, through a variable, concatenated into the message or formatted with String.format

    • Numeric parameters, and values whose line breaks are replaced, encoded or escaped before logging, are not reported

Vulnerable code example

import lombok.extern.slf4j.Slf4j;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;

@Slf4j
@RestController
class UploadController {...

✅ Secure code example

import lombok.extern.slf4j.Slf4j;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;

@Slf4j
@RestController
class UploadController {...