Home / Vulnerability Database / Java : Logging into system output
Java

Java : Logging into system output

Classification

Overview

The application uses unstructured logging (error messages are outputted to standard out or err). Instead, it is recommended to use a structured logging, which can generate a log with the levels, time stamps, standard formatting. Using standard streams to output error messages while there is a mechanism of structured logging in a program can lead to absence of critical information in the log.

Outputting error messages to standard streams is only permissible on the early stages of development.

LOW

DerScanner Severity Score

Do you want to fix Java : Logging into system output in your application?

See also

Java

Java : Race condition

Java

Java : Text4Shell Vulnerability

Java

Java : JNI usage