Restrict a debug endpoint to admins
auth-debug-endpoint
A debug endpoint was reachable during the scan. If it prints internal state, restrict it to the intended accounts, or drop it from production builds.
Why this matters
A debug endpoint was reachable during the scan. It can expose internal state and system details — more sensitive than typical reconnaissance — conditionally exploitable depending on what data is exposed.
Web servers
Frameworks
Nginx
- 1 Block access to debug endpoints at the proxy level
nginx
location ~ ^/(debug|_debug|__debug) {
deny all;
return 404;
}Does your app still have this?
Scan your domain