id: django-debug-config-enabled info: name: Django Debug Configuration Enabled author: dhiyaneshDK,hackergautam severity: medium description: Django debug configuration is enabled, which allows an attacker to obtain system configuration information such as paths or settings. metadata: max-request: 1 tags: django,debug,misconfig http: - method: GET path: - "{{BaseURL}}/NON_EXISTING_PATH/" matchers-condition: and matchers: - type: word words: - URLconf defined - Page not found - Django tried these URL patterns, in this order condition: and - type: status status: - 404 # digest: 4b0a00483046022100a6816682161bdcb94b624de3af130ab6852ca6c686c06d454023df9f01ab48a7022100ea2c2b3401e3e1cf9f099aeafa5b5d7e0ba951ff51bbfa1dd5543d312be48a72:922c64590222798bb761d5b6d8e72950