Debugging enabled in production
Description
The system has the debug mode active which generates an information leak when an error is generated.
Impact
Obtain sensitive information such as stacktraces and versions of the systems used.
Recommendation
Make sure that debugging mode is not enabled in the production environment and remove statements or portions of code that are executing in debugging mode.
Threat
External attacker with access to the application.
Expected Remediation Time
⏱️ 15 minutes.
Rules
Http X Chromelogger Data LeakXml Dev Mode EnabledPhp Debug Mode EnabledJavascript Error Handler Used In ProductionRuby Error Information DisclosureTypescript Error Handler Used In ProductionDocker Debug Enabled In DockerfilePython Debug Mode Enabled FlaskPython Debug True In SettingsPython Debug Mode EnabledJavascript Debugger Statement PresentConfig Files Debug True In Web ConfigTypescript Debugger Statement PresentJava Webview Debugging EnabledRuby Debugger Mode Use