CWE-489
Overview
- CWE ID
- 489
- CWE Name
- Active Debug Code
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Draft
Description
The application is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
Extended Description
A common development practice is to add "back door" code specifically designed for debugging or testing purposes that is not intended to be shipped or deployed with the application. These back door entry points create security risks because they are not c