Weaknesses of type CWE-489

93 results

Código de depuração deixado em produção

Código temporário de debug — logs verbosos, print statements, rotas de teste, funcionalidades desativadas com comentários — permanece na aplicação em produção. Isso expõe informações sensíveis (stack traces, caminhos internos, tokens) e pode criar portas traseiras acidentais que atacantes exploram para contornar autenticação ou acessar recursos restritos.

Example

Um desenvolvedor deixa um endpoint `/admin/test` acessível sem autenticação para testar fluxos, ou uma função de debug que imprime credenciais no log de erros. Um atacante descobre e usa isso para ganhar acesso administrativo ou extrair secrets.

How to mitigate

Remova todo código de debug antes do merge para produção (code review obrigatório), use variáveis de ambiente para controlar níveis de log (nunca verbose em prod), e automatize a detecção com linters que flagrem console.log, print() ou rotas de teste conhecidas. Mantenha debug apenas em branches isolados ou ambientes de staging.

CVE-2020-25156HIGHB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 1.2%CVE-2023-22357CRITICALActive debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execuEPSS 1.2%CVE-2022-33323HIGHAuthentication Bypass Vulnerability in Robot Controller of MELFA SD/SQ series and F-seriesEPSS 1.1%CVE-2024-29511HIGHArtifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and EPSS 1.1%CVE-2023-1618HIGHAuthentication Bypass Vulnerability in MELSEC WS Series Ethernet Interface ModuleEPSS 1.1%CVE-2019-10939A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET varEPSS 1.1%CVE-2023-49593HIGHLeftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted neEPSS 1.1%CVE-2026-9133HIGHArbitrary file read in rabbitmq-aws pluginEPSS 1.0%CVE-2022-28689MEDIUMA leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted EPSS 1.0%CVE-2022-32760HIGHA denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9ZEPSS 0.9%CVE-2022-30543MEDIUMA leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted seEPSS 0.9%CVE-2024-21827HIGHA leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 2024EPSS 0.9%CVE-2022-45677CRITICALSQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.EPSS 0.9%CVE-2023-4804CRITICALQuantum HD UnityEPSS 0.8%CVE-2022-26023MEDIUMA leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted sEPSS 0.8%CVE-2021-23861MEDIUMPossible Access to Debug Functions in Bosch VRM / BVMSEPSS 0.8%CVE-2022-29481MEDIUMA leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted seEPSS 0.8%CVE-2024-46873CRITICALMultiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote EPSS 0.7%CVE-2023-0954HIGHDebug feature in Sensormatic Electronics Illustra Dome and PTZ camerasEPSS 0.7%CVE-2024-9644CRITICALFour-Faith F3x36 bapply.cgi Auth BypassEPSS 0.7%