<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Information Disclosure in HTTP response header in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/information-disclosure-in-http-response-header/m-p/144580#M38367</link>
    <description>&lt;P&gt;A response header is an HTTP header that can be used in an HTTP response and that doesn't relate to the content of the message. Response headers, like Age, Location or Server are used to give a more detailed context of the response.&lt;/P&gt;&lt;P&gt;Penetration tester found that there is sensitive information related to the server version in the HTTP response header and the version of the web application framework used.&lt;/P&gt;&lt;P&gt;Exposing details of the server version and web application technology can increase the likelihood of attackers efficiently exploiting servers with known knowledge.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Mar 2023 03:14:53 GMT</pubDate>
    <dc:creator>leochan168</dc:creator>
    <dc:date>2023-03-27T03:14:53Z</dc:date>
    <item>
      <title>Information Disclosure in HTTP response header</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/information-disclosure-in-http-response-header/m-p/144580#M38367</link>
      <description>&lt;P&gt;A response header is an HTTP header that can be used in an HTTP response and that doesn't relate to the content of the message. Response headers, like Age, Location or Server are used to give a more detailed context of the response.&lt;/P&gt;&lt;P&gt;Penetration tester found that there is sensitive information related to the server version in the HTTP response header and the version of the web application framework used.&lt;/P&gt;&lt;P&gt;Exposing details of the server version and web application technology can increase the likelihood of attackers efficiently exploiting servers with known knowledge.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 03:14:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/information-disclosure-in-http-response-header/m-p/144580#M38367</guid>
      <dc:creator>leochan168</dc:creator>
      <dc:date>2023-03-27T03:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Information Disclosure in HTTP response header</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/information-disclosure-in-http-response-header/m-p/144581#M38368</link>
      <description>&lt;P&gt;There are different actions that may be taken to patch this vulnerability. Since Alfresco is installed behind a HTTP Web Proxy (NGINX by default), following configuration will avoid to expose unwanted information in HTTP responses:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://medium.com/@getpagespeed/how-to-remove-the-server-header-in-nginx-e74c7b431b" target="_blank" rel="nofollow noopener noreferrer"&gt;https://medium.com/@getpagespeed/how-to-remove-the-server-header-in-nginx-e74c7b431b&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 08:01:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/information-disclosure-in-http-response-header/m-p/144581#M38368</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2023-03-27T08:01:31Z</dc:date>
    </item>
  </channel>
</rss>

