VYPR

CWE-215

Insertion of Sensitive Information Into Debugging Code

BaseDraft

Description

The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.

When debugging, it may be necessary to report detailed information to the programmer. However, if the debugging code is not disabled when the product is operating in a production environment, then this sensitive information may be exposed to attackers.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (24)

page 2 of 2
  • CVE-2025-0895LowMar 2, 2025
    risk 0.16cvss 2.4epss 0.00

    IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log messages.

  • CVE-2024-22194LowJan 11, 2024
    risk 0.07cvss 2.2epss 0.00

    cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` in unpatched versions…

  • CVE-2026-44934HigJul 6, 2026
    risk 0.00cvss —epss 0.00

    A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials.

  • CVE-2023-51390MedDec 21, 2023
    risk 0.00cvss 6.5epss 0.00

    journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential…