- What is CWE-615?
- While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.
- What CVEs are caused by CWE-615?
- 3 recorded CVEs are attributed to CWE-615, including CVE-2024-52298, CVE-2026-3157, CVE-2026-3158.
- How do you prevent CWE-615?
- Remove comments which have sensitive information about the design/implementation of the application. Some of the comments may be exposed to the user and affect the security posture of the application.
- How is CWE-615 detected?
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
- What are the consequences of CWE-615?
- Exploiting CWE-615 can lead to: Read Application Data.
- Is CWE-615 actively exploited?
- 3 recorded CVEs are caused by CWE-615; none are currently in CISA's KEV catalog of actively exploited flaws.