Nginx server version disclosure on engineeringblog
None
Y
Yelp
Submitted None
Actions:
Reported by
japz
Vulnerability Details
Technical details and impact analysis
Hi Yelp Team,
I have found a little information disclosure on your system with regards to the version of server you are using, due to not properly handling 404 errors , whe you go to the page that i not existing, the exact nginx version was disclosed.
__PoC URL:__ engineeringblog.yelp.com/test
__PoC Screenshot:__ {F33044}
It is important to keep secret of the exact server versions.
__Mitigation:__
You may want to create a customize 404 error page, or you can just simply remove the nginx server version.
Regards
Japz
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Information Disclosure