Falhas do tipo CWE-489

94 resultados

Código de debug deixado em produção

É quando código temporário de desenvolvimento (prints, logs detalhados, flags de debug, endpoints secretos) permanece ativo na aplicação em produção. Isso expõe informações sensíveis, permite bypass de controles de segurança e facilita ataques porque o atacante consegue enxergar o funcionamento interno da aplicação.

Exemplo

Um desenvolvedor deixa um print() mostrando a senha do banco de dados, ou uma flag de debug que desativa validação de login, ou um endpoint não documentado que retorna dados administrativos. Quando o código vai para produção, qualquer pessoa com acesso consegue explorar isso.

Como mitigar

Remova todo código de debug antes do build em produção (use variáveis de ambiente ou compilação condicional). Implemente revisão de código e testes automatizados que verifiquem a ausência de flags de debug. Use ferramentas de análise estática para detectar pontos suspeitos deixados para trás.

CVE-2020-25156HIGHB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 1.2%CVE-2023-22357CRITICALActive debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execuEPSS 1.2%CVE-2022-33323HIGHAuthentication Bypass Vulnerability in Robot Controller of MELFA SD/SQ series and F-seriesEPSS 1.1%CVE-2024-29511HIGHArtifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and EPSS 1.1%CVE-2023-1618HIGHAuthentication Bypass Vulnerability in MELSEC WS Series Ethernet Interface ModuleEPSS 1.1%CVE-2019-10939A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET varEPSS 1.1%CVE-2023-49593HIGHLeftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted neEPSS 1.1%CVE-2026-9133HIGHArbitrary file read in rabbitmq-aws pluginEPSS 1.0%CVE-2022-28689MEDIUMA leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted EPSS 1.0%CVE-2022-32760HIGHA denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9ZEPSS 0.9%CVE-2022-30543MEDIUMA leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted seEPSS 0.9%CVE-2024-21827HIGHA leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 2024EPSS 0.9%CVE-2022-45677CRITICALSQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.EPSS 0.9%CVE-2023-4804CRITICALQuantum HD UnityEPSS 0.8%CVE-2022-26023MEDIUMA leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted sEPSS 0.8%CVE-2021-23861MEDIUMPossible Access to Debug Functions in Bosch VRM / BVMSEPSS 0.8%CVE-2022-29481MEDIUMA leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted seEPSS 0.8%CVE-2024-46873CRITICALMultiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote EPSS 0.7%CVE-2023-0954HIGHDebug feature in Sensormatic Electronics Illustra Dome and PTZ camerasEPSS 0.7%CVE-2024-9644CRITICALFour-Faith F3x36 bapply.cgi Auth BypassEPSS 0.7%