Weaknesses of type CWE-489

94 results

Código de depuração deixado em produção

Código temporário de debug — logs verbosos, print statements, rotas de teste, funcionalidades desativadas com comentários — permanece na aplicação em produção. Isso expõe informações sensíveis (stack traces, caminhos internos, tokens) e pode criar portas traseiras acidentais que atacantes exploram para contornar autenticação ou acessar recursos restritos.

Example

Um desenvolvedor deixa um endpoint `/admin/test` acessível sem autenticação para testar fluxos, ou uma função de debug que imprime credenciais no log de erros. Um atacante descobre e usa isso para ganhar acesso administrativo ou extrair secrets.

How to mitigate

Remova todo código de debug antes do merge para produção (code review obrigatório), use variáveis de ambiente para controlar níveis de log (nunca verbose em prod), e automatize a detecção com linters que flagrem console.log, print() ou rotas de teste conhecidas. Mantenha debug apenas em branches isolados ou ambientes de staging.

CVE-2022-38453LOWContec Health CMS8000EPSS 0.2%CVE-2026-54799HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < VEPSS 0.2%CVE-2023-21496MEDIUMActive Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting EPSS 0.2%CVE-2026-33201HIGHDigital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vulnerability is exploiEPSS 0.2%CVE-2025-54660MEDIUMAn active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWEPSS 0.2%CVE-2025-1479MEDIUMAn open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to exEPSS 0.2%CVE-2025-2486LOWUEFI Shell accessible in AAVMF with Secure Boot enabled on UbuntuEPSS 0.1%CVE-2026-81943HIGHPLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCEEPSS 0.1%CVE-2025-30185HIGHActive debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. SEPSS 0.1%CVE-2026-6485HIGHUEFI BIOS embedded Shell can be used to bypass Secure BootEPSS 0.1%CVE-2025-36899HIGHThere is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation ofEPSS 0.1%CVE-2025-21472MEDIUMLeftover Debug Code in Secure ElementEPSS 0.1%CVE-2024-44092HIGHThere is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalatEPSS 0.1%CVE-2026-50228MEDIUMElectron DevTools Arbitrary Code Execution Vulnerability in NitroSenseEPSS