Server version disclosure

Disclosed: 2016-07-07 23:01:36 By japz To uber
Unknown
Vulnerability Details
Hi uber, maybe this is a low risk but i want to report that the __nginx__ and __openresty__ server version are being disclosed. __For openresty:__ Accessing this url: https://chef.uberinternal.com/ will give you an error "502 Bad Gateway" but you can see on the page that the server version was disclose (openresty/1.9.3.1). See screenshot (openresty.JPG). __For Nginx:__ When you go to this URL: __http://it-tools.uberinternal.com/__ , it will redirect to JetBrains but you will see in the response header that the __nginx/1.8.0__ version was disclosed. See screen shots (nginx_1.JPG and nginx_2.JPG) It is important to keep secret of server versions. Similar reports here: #141125 Cheers Japz
Actions
View on HackerOne
Report Stats
  • Report ID: 149483
  • State: Closed
  • Substate: informative
  • Upvotes: 12
Share this report