Property
Languagehcl
Severitylow
CWECWE-778: Insufficient Logging
OWASPA10:2017 - Insufficient Logging & Monitoring
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The App Service resource in Azure is not configured to enable failed request tracing. Without this setting, important information about failed requests may not be logged, making it harder to diagnose issues or investigate suspicious activity.

Impact#

If failed request tracing is disabled, security incidents or operational problems could go undetected or unresolved, as there would be insufficient logs to identify what went wrong. This can hinder incident response and leave the application vulnerable to undetected attacks or misconfigurations.