Nginx server version disclosure on engineeringblog

Disclosed: 2017-11-09 20:10:13 By japz To yelp
None
Vulnerability Details
Hi Yelp Team, I have found a little information disclosure on your system with regards to the version of server you are using, due to not properly handling 404 errors , whe you go to the page that i not existing, the exact nginx version was disclosed. __PoC URL:__ engineeringblog.yelp.com/test __PoC Screenshot:__ {F33044} It is important to keep secret of the exact server versions. __Mitigation:__ You may want to create a customize 404 error page, or you can just simply remove the nginx server version. Regards Japz
Actions
View on HackerOne
Report Stats
  • Report ID: 180346
  • State: Closed
  • Substate: informative
  • Upvotes: 4
Share this report