Weaknesses of type CWE-489

94 results

Código de depuração deixado em produção

Código temporário de debug — logs verbosos, print statements, rotas de teste, funcionalidades desativadas com comentários — permanece na aplicação em produção. Isso expõe informações sensíveis (stack traces, caminhos internos, tokens) e pode criar portas traseiras acidentais que atacantes exploram para contornar autenticação ou acessar recursos restritos.

Example

Um desenvolvedor deixa um endpoint `/admin/test` acessível sem autenticação para testar fluxos, ou uma função de debug que imprime credenciais no log de erros. Um atacante descobre e usa isso para ganhar acesso administrativo ou extrair secrets.

How to mitigate

Remova todo código de debug antes do merge para produção (code review obrigatório), use variáveis de ambiente para controlar níveis de log (nunca verbose em prod), e automatize a detecção com linters que flagrem console.log, print() ou rotas de teste conhecidas. Mantenha debug apenas em branches isolados ou ambientes de staging.

CVE-2022-27597LOWQTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)EPSS 0.7%CVE-2024-28008CRITICALActive Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MEPSS 0.6%CVE-2024-36475HIGHFutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user EPSS 0.6%CVE-2025-46674LOWNASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading tEPSS 0.6%CVE-2026-40035CRITICALUnfurl - Werkzeug Debugger Exposure via String Config ParsingEPSS 0.6%CVE-2024-32047CRITICALCyberPower PowerPanel business Active Debug CodeEPSS 0.5%CVE-2022-46156HIGHGrafana's default installation of `synthetic-monitoring-agent` exposes sensitive informationEPSS 0.5%CVE-2026-58378HIGHAllwinner TV Box TV98 ADB exposed on networkEPSS 0.4%CVE-2026-58191MEDIUMAppium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routesEPSS 0.4%CVE-2026-54798HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < VEPSS 0.4%CVE-2026-59092HIGHJuiceFS - Authentication Bypass via pprof and metrics EndpointsEPSS 0.4%CVE-2021-1398MEDIUMCisco IOS XE Software Arbitrary Code Execution VulnerabilityEPSS 0.4%CVE-2025-2919HIGHNetis WF-2404 UART hardware allows activation of test or debug logic at runtimeEPSS 0.4%CVE-2023-4227MEDIUMioLogik 4000 Series: Existence of an Unauthorized ServiceEPSS 0.4%CVE-2026-41186MEDIUMUnauthenticated Go pprof exposure in Calico debug serverEPSS 0.3%CVE-2024-31406HIGHActive debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticatEPSS 0.3%CVE-2026-53952CRITICALGetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic FlawEPSS 0.3%CVE-2026-49188HIGHElevated Root Command Execution via ai_cmd SocketsEPSS 0.3%CVE-2026-32662MEDIUMGardyn Cloud API Active Debug CodeEPSS 0.3%CVE-2024-53648HIGHA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 EPSS 0.3%