Description
The web application exposes Python debugpy/ debugger port. It's not recommended to have the server publicly accessible as the debugger has full access to the Python execution environment and an attacker may be able to execute arbitrary python code.
Remediation
Disable debugger or restrict access to it
References
Related Vulnerabilities
Docker Engine API is accessible without authentication
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-11145)
Axis system configuration listing enabled in WEB-INF/server-config.wsdd
WordPress Plugin Login by Auth0 Multiple Vulnerabilities (3.11.3)
SAP NetWeaver Java AS WD_CHAT information disclosure vulnerability