Falhas do tipo CWE-1258

15 resultados

Exposição de informações sensíveis do sistema via dados de debug não limpos

Ocorre quando informações de depuração (variáveis, caminhos internos, tokens, credenciais) deixadas no código ou binário em produção são acessíveis a atacantes. O desenvolvedor esqueceu de remover ou desabilitar logs, símbolos de debug ou modo verbose antes de deployar, expondo detalhes que facilitam ataques direcionados.

Exemplo

Um aplicativo mobile compilado com símbolos de debug intactos permite que um atacante use ferramentas como IDA Pro ou Ghidra para reverter o código e encontrar URLs internas, nomes de funções sensíveis e até credenciais hardcoded em strings de log. Outra situação: um servidor que deixa endpoints de debug habilitados em produção, retornando stack traces completos com caminhos do sistema de arquivos e versões de bibliotecas.

Como mitigar

Remova ou desabilite toda a instrumentação de debug antes do build de produção (strip de símbolos, desabilitar logs verbosos, remover endpoints de debug). Use variáveis de ambiente para controlar níveis de logging e implemente verifications no pipeline CI/CD que bloqueiem deploys com código de debug detectado.

CVE-2024-36912CRITICALDrivers: hv: vmbus: Track decrypted status in vmbus_gpadlEPSS 1.0%CVE-2022-31162HIGHSlack Morphism for Rust before 0.41.0 can accidentally leak Slack OAuth client information in application debug logsEPSS 0.9%CVE-2025-32257MEDIUMWordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerabilityEPSS 0.8%CVE-2022-39292HIGHExposure of sensitive Slack webhook URLs in debug logs and tracesEPSS 0.7%CVE-2024-36913CRITICALDrivers: hv: vmbus: Leak pages if set_memory_encrypted() failsEPSS 0.7%CVE-2023-48308LOWCalendar app returns full stacktrace when an error happens while editing appointmentEPSS 0.5%CVE-2026-66432HIGHWordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-15480LOWSenstive information disclosure was affecting ubuntu-desktop-provisionEPSS 0.3%CVE-2025-26482MEDIUMDell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with EPSS 0.3%CVE-2026-26948MEDIUMDell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an ExpEPSS 0.3%CVE-2025-14551LOWSenstive information disclosure was affecting subiquityEPSS 0.3%CVE-2026-52696HIGHWordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2022-43666LOWExposure of sensitive system information due to uncleared debug information for some Intel Unison software may allow an authenticated user tEPSS 0.2%CVE-2026-80239LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of SensiEPSS 0.1%CVE-2026-79727LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of SensiEPSS 0.1%