Version Disclosure (Apache Traffic Server)
Summary#
Invicti identified a version disclosure (Apache Traffic Server) in the target web server's HTTP response. Apache Traffic Server is a fast, scalable and extensible HTTP/1.1 and HTTP/2.0 compliant caching proxy server.
This information can help an attacker gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Apache Traffic Server.
Impact#
An attacker might use the disclosed information to harvest specific security vulnerabilities for the version identified.
Remediation#
Configure your web server to prevent information leakage from the
X-Powered-By
header of its HTTP response.
Classifications#