Skip to content

Detailed Exceptions Enabled

Description

The `consider_all_requests_local` setting is enabled, which can expose sensitive system or application information to end users, potentially aiding attackers in crafting further attacks.

Examples

Insecure Code

ruby
config.consider_all_requests_local = true

Secure Code

ruby
config.consider_all_requests_local = false

Remediation

Set `config.consider_all_requests_local` to `false` in production environments.

Rule Details

FieldValue
IDCODE-0530
CategoryInsecureConfig
SeverityMEDIUM
CWECWE-209
ConfidenceHIGH
ImpactHIGH
LikelihoodMEDIUM
ExploitabilityEASY
Tagserror handling, sensitive data exposure
OWASPA3:2017-Sensitive Data Exposure, A05:2021-Security Misconfiguration

References