Fallos del tipo CWE-489

86 resultados

Código de depuração remanescente em produção

É quando código de debug (prints, logs verbosos, funcionalidades de teste ou backdoors de desenvolvimento) fica presente na versão de produção. Isso expõe informações sensíveis (caminhos, tokens, lógica interna) e pode oferecer pontos de entrada para atacantes explorarem recursos que deveriam estar desativados.

Ejemplo

Um desenvolvedor deixa uma função de admin acessível sem autenticação apenas para testar, ou mantém prints mostrando valores de variáveis sensíveis nos logs de produção. Quando o atacante vê essas mensagens ou descobre a função de teste, consegue ganhar acesso ou contornar controles de segurança.

Cómo mitigar

Remova todo código de debug antes do deploy (use flags de compilação ou variáveis de ambiente para desativar logs verbosos em produção). Implemente revisão de código e testes automatizados que detectem funções de teste expostas; use ferramentas que identificam blocos de debug antes do commit.

CVE-2024-7756MEDIUMA potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges bEPSS 0.3%CVE-2021-1381MEDIUMCisco IOS XE Software Active Debug Code VulnerabilityEPSS 0.3%CVE-2026-59092HIGHJuiceFS - Authentication Bypass via pprof and metrics EndpointsEPSS 0.3%CVE-2024-41999MEDIUMSmart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an atEPSS 0.3%CVE-2025-42872MEDIUMCross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise PortalEPSS 0.3%CVE-2025-15017HIGHA vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical accEPSS 0.3%CVE-2026-27131MEDIUMSprig Plugin for Craft CMS potentially discloses sensitive information via Sprig PlaygroundEPSS 0.3%CVE-2026-58191MEDIUMAppium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routesEPSS 0.3%CVE-2026-58378HIGHAllwinner TV Box TV98 ADB exposed on networkEPSS 0.2%CVE-2026-54798HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < VEPSS 0.2%CVE-2026-41186MEDIUMUnauthenticated Go pprof exposure in Calico debug serverEPSS 0.2%CVE-2025-52663HIGHA vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This iEPSS 0.2%CVE-2024-29075MEDIUMActive debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, EPSS 0.2%CVE-2025-7705HIGHAuthentication bypass due to compatibility mode enabled by defaultEPSS 0.2%CVE-2023-21496MEDIUMActive Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting EPSS 0.2%CVE-2022-38453LOWContec Health CMS8000EPSS 0.2%CVE-2026-33201HIGHDigital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vulnerability is exploiEPSS 0.2%CVE-2026-65893HIGHArbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP CameraEPSS 0.2%CVE-2025-54660MEDIUMAn active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWEPSS 0.2%CVE-2025-1479MEDIUMAn open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to exEPSS 0.1%