CWE-489: Active Debug Code
The product is released with debugging code still enabled or active.
Browse cwe in distribution with official CWE context and Glexia analysis.
Search And Filters
Showing 5 of 5 CWE records.
The product is released with debugging code still enabled or active.
The product stores a CVS, git, or other repository in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.
Accessible test applications can pose a variety of security risks. Since developers or administrators rarely consider that someone besides themselves would even know about the existence of these applications, it is common for them to contain sensitive information or functions.
The product writes sensitive information to a log file.
While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.