CWE Database
/

CWE-531

Back to CWE list

CWE-531

Inclusion of Sensitive Information in Test Code

Variant
Incomplete

Description

Accessible test applications can pose a variety of security risks. Since developers or administrators rarely consider that someone besides themselves would even know about the existence of these applications, it is common for them to contain sensitive information or functions.

Common Consequences

Scope

Confidentiality

Impact

Read Application Data

Potential Mitigations

Distribution
Installation

Remove test code before deploying the application into production.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now