Weaknesses of type CWE-1258

16 results

Exposição de informações sensíveis do sistema via dados de debug não removidos

Quando código de produção contém informações de debug (logs detalhados, stack traces, variáveis internas, caminhos de arquivo, endereços de memória) que não são removidas ou desabilitadas em ambiente produtivo. Um atacante pode extrair essas informações para mapear a arquitetura do sistema, identificar tecnologias usadas, versões de bibliotecas vulneráveis ou até credenciais acidentalmente logadas.

Example

Uma API em produção retorna um erro HTTP 500 com stack trace completo mostrando caminhos absolutos do servidor, nomes de variáveis internas e versão exata do framework; ou um aplicativo mobile deixa logs de debug ativados que expõem tokens de sessão e queries de banco de dados quando o dispositivo é analisado.

How to mitigate

Remova ou desabilite logs e informações de debug antes de fazer deploy em produção (use flags de compilação, variáveis de ambiente ou níveis de log configuráveis). Retorne mensagens de erro genéricas para o usuário final enquanto loga detalhes sensíveis apenas internamente em arquivos protegidos e auditados.

CVE-2024-36912CRITICALDrivers: hv: vmbus: Track decrypted status in vmbus_gpadlEPSS 1.0%CVE-2022-31162HIGHSlack Morphism for Rust before 0.41.0 can accidentally leak Slack OAuth client information in application debug logsEPSS 0.9%CVE-2025-32257MEDIUMWordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerabilityEPSS 0.8%CVE-2022-39292HIGHExposure of sensitive Slack webhook URLs in debug logs and tracesEPSS 0.7%CVE-2024-36913CRITICALDrivers: hv: vmbus: Leak pages if set_memory_encrypted() failsEPSS 0.7%CVE-2023-48308LOWCalendar app returns full stacktrace when an error happens while editing appointmentEPSS 0.5%CVE-2026-26948MEDIUMDell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an ExpEPSS 0.5%CVE-2026-52696HIGHWordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-66432HIGHWordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-15480LOWSenstive information disclosure was affecting ubuntu-desktop-provisionEPSS 0.3%CVE-2025-26482MEDIUMDell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with EPSS 0.3%CVE-2025-14551LOWSenstive information disclosure was affecting subiquityEPSS 0.3%CVE-2022-43666LOWExposure of sensitive system information due to uncleared debug information for some Intel Unison software may allow an authenticated user tEPSS 0.2%CVE-2026-80239LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of SensiEPSS 0.2%CVE-2026-65127MEDIUMNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information dEPSS 0.2%CVE-2026-79727LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of SensiEPSS 0.1%