You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An unauthenticated user can see in the footer the product name and the version.
This makes it very easy for automatic crawlers find public websites and their open exploits to gain access.
These infos should be hidden for unauthenticated users especially how relevant the product is (containing lots of login data which makes it a potential high target)
Expectation
Remove footer for unatuhenticated users.
Error & Logs
No response
Execution environment
No response
Containerization
Docker
Additional information
No response
The text was updated successfully, but these errors were encountered:
Hi,
I agree the version number can ease finding an exposed instance. I am a bit skeptical for the product name.
Anyway, I added the request to the backlog, will think about it.
Version
2.5.3
Details & Steps to reproduce
An unauthenticated user can see in the footer the product name and the version.
This makes it very easy for automatic crawlers find public websites and their open exploits to gain access.
These infos should be hidden for unauthenticated users especially how relevant the product is (containing lots of login data which makes it a potential high target)
Expectation
Remove footer for unatuhenticated users.
Error & Logs
No response
Execution environment
No response
Containerization
Additional information
No response
The text was updated successfully, but these errors were encountered: