Nginx server version disclosure on engineeringblog
None
Vulnerability Details
Hi Yelp Team,
I have found a little information disclosure on your system with regards to the version of server you are using, due to not properly handling 404 errors , whe you go to the page that i not existing, the exact nginx version was disclosed.
__PoC URL:__ engineeringblog.yelp.com/test
__PoC Screenshot:__ {F33044}
It is important to keep secret of the exact server versions.
__Mitigation:__
You may want to create a customize 404 error page, or you can just simply remove the nginx server version.
Regards
Japz
Actions
View on HackerOneReport Stats
- Report ID: 180346
- State: Closed
- Substate: informative
- Upvotes: 4