bito-code-review[bot] commented on PR #44666:
URL: https://github.com/apache/superset/pull/44666#issuecomment-5849579885
<!-- Bito Reply -->
The flagged security issue is correct. Logging attacker-controlled input
like `request.path` or exception descriptions directly can lead to log
injection, where an attacker uses newline characters to forge log entries. To
resolve this, you should sanitize the input by replacing or escaping newline
characters before logging.
Here is a concise fix for `superset/views/error_handling.py`:
```python
if status == 404:
# Sanitize path to prevent log injection
safe_path = request.path.replace("\n", "").replace("\r", "")
logger.debug("HTTPException: 404 %s", safe_path)
elif status < 500:
# Sanitize exception description
safe_ex = str(ex).replace("\n", "").replace("\r", "")
logger.warning("HTTPException: %s", safe_ex)
```
There are no other comments on this PR to address. Would you like me to
check for any other potential security improvements in this file?
**superset/views/error_handling.py**
```
if status == 404:
# Sanitize path to prevent log injection
safe_path = request.path.replace("\n", "").replace("\r", "")
logger.debug("HTTPException: 404 %s", safe_path)
elif status < 500:
# Sanitize exception description
safe_ex = str(ex).replace("\n", "").replace("\r", "")
logger.warning("HTTPException: %s", safe_ex)
```
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]