10037Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)

PUBLISHEDsecurity alertLow
Passive

Metadata

Alert ID:
10037
Risk:
Low
Type:
Passive

摘要

The web/application server is leaking information via one or more “X-Powered-By” HTTP response headers. Access to such information may facilitate attackers identifying other frameworks/components your web application is reliant upon and the vulnerabilities such components may be subject to.

解决方案

Ensure that your web server, application server, load balancer, etc. is configured to suppress "X-Powered-By" headers.

参考