# CRLF injection issue (Improper Output Neutralization for Logs) /src/lib/connectors/xhr.js 76

**URL:** <https://discuss.elastic.co/t/crlf-injection-issue-improper-output-neutralization-for-logs-src-lib-connectors-xhr-js-76/130325>\
**Category:** Elasticsearch\
**Created:** [May 2, 2018, 8:46pm UTC](https://discuss.elastic.co/t/crlf-injection-issue-improper-output-neutralization-for-logs-src-lib-connectors-xhr-js-76/130325 "2018-05-02T20:46:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![smaeung](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smaeung/32/30732_2.png) [@smaeung](https://discuss.elastic.co/u/smaeung)\
**Post date:** [May 2, 2018, 8:46pm UTC](https://discuss.elastic.co/t/crlf-injection-issue-improper-output-neutralization-for-logs-src-lib-connectors-xhr-js-76/130325/1 "2018-05-02T20:46:53Z")

</div>

Hi, all

we used a node project that used for elasticsearch javascript pacakge ( 14.2.2) which is the latest version.

We have got security audit report by a security firm that based on elasticsearch (14.2.2) for javascript package that it is possible to have CRLF injection issue (Improper Output Neutralization for Logs) on /src/lib/connectors/xhr.js 76

whether it is possible to have a log forging attack by line#76

```
73: xhr.onreadystatechange = function () {
74: if (xhr.readyState === 4) {
75: clearTimeout(timeoutId);
76: log.trace(params.method, url, params.body, xhr.responseText, xhr.status);
      var err = xhr.status ? void 0 : new ConnectionFault(xhr.statusText || 'Request failed to complete.');
      cb(err, xhr.responseText, xhr.status);
    }
  };

```

is it already identified from elasticsearch community ? or any configuration set up to make disable log.trace() ?

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [May 3, 2018, 3:53am UTC](https://discuss.elastic.co/t/crlf-injection-issue-improper-output-neutralization-for-logs-src-lib-connectors-xhr-js-76/130325/2 "2018-05-03T03:53:52Z")

</div>

The `log` is just a logger abstraction which can be implemented in many different ways.

If you need extra logic due to security concerns, then you can just [implement and use your own logger](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/current/logging.html).

---

<div class="post-metadata">

**Author:** ![smaeung](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smaeung/32/30732_2.png) [@smaeung](https://discuss.elastic.co/u/smaeung)\
**Post date:** [May 3, 2018, 4:00am UTC](https://discuss.elastic.co/t/crlf-injection-issue-improper-output-neutralization-for-logs-src-lib-connectors-xhr-js-76/130325/3 "2018-05-03T04:00:24Z")

</div>

thanks for the information. I set up as below disable trace, only enable for error.

`var client = new elasticsearch.Client({ log: 'error' });`

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [May 3, 2018, 4:01am UTC](https://discuss.elastic.co/t/crlf-injection-issue-improper-output-neutralization-for-logs-src-lib-connectors-xhr-js-76/130325/4 "2018-05-03T04:01:38Z")

</div>

Yes, that will also work 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 4:01am UTC](https://discuss.elastic.co/t/crlf-injection-issue-improper-output-neutralization-for-logs-src-lib-connectors-xhr-js-76/130325/5 "2018-05-31T04:01:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
