ASVS Requirement 16.5.1
- Level: 2
- Chapter: V16 Security Logging and Error Handling
- Section: V16.5 Error Handling
- Source: 0x25-V16-Security-Logging-and-Error-Handling.md
Description
Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.