Skip to content

SIEM delivery logs the full sink URL, credentials and all #728

Description

@rubenvdlinde

SiemTransport::deliverWebhook() posts to $sink->getEndpoint(). A non-2xx answer throws a Guzzle exception whose message names the full URL, and DeliverSiemEventsJob.php line 72 logs that message. A sink URL that carries a token in a query parameter therefore lands in nextcloud.log. SiemService.php line 383 has the same shape.

Found while fixing #707, which was the same defect on the breach path. This one is smaller: the endpoint is admin configuration, not something a user typed, and no user id is stamped beside it. It is still a credential in a log file.

Two neighbours worth checking in the same pass: ScanExpiringSecretsJob.php line 110 and ScanCertificateExpiryJob.php line 105 both log a record id together with an unbounded exception message.

The connection reporter is already clean: reportSiemDrain() carries counts, and atHost() names a host only, which REQ-KEEPIQ-CONN-003 requires.

What to do

Done when no log line written by the SIEM path can contain a sink URL or a token.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingsecurityA user can read or write what they must nottriageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions