Http Server Header Leaks Technical Info
Description
Detects when an HTTP Server response header exposes detailed technical information like version numbers that could help attackers identify vulnerable server software versions. This information disclosure vulnerability allows attackers to more easily determine which known vulnerabilities might affect the server.
Detection Strategy
• Examines the HTTP Server header in web server responses
• Triggers when the Server header contains version numbers (e.g., Apache/2.4.1, nginx/1.18.0)
• Reports a vulnerability when specific version information is found in the header value
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.