Uploaded image for project: 'JBoss Core Services'
  1. JBoss Core Services
  2. JBCS-739

JBCS SP1 changed the server header

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • httpd 2.4.37 ER2
    • httpd 2.4.29 SP1 GA
    • httpd
    • None
    • +
    • Workaround Exists
    • Hide

      Use mod_security SecServerSignature.

      Show
      Use mod_security SecServerSignature.
    • Hide

      Make a request and see the Server header on the response.

      Show
      Make a request and see the Server header on the response.

      After applied SP1 patch to JBCS 2.4.29 changed the server header from Apache to JBCS:

      ~~~
      Server version: JBCS httpd/2.4.29-SP1-35 (Red Hat)
      Server built: Nov 23 2018 16:02:23
      ~~~

      With ServerTokens Prod, the server header remains as:

      ~~~
      Server: JBCS httpd
      ~~~

      The header is disclosing vendor information, should be good if revert to "Server: Apache".

            pprokopi@redhat.com Petros Marios Prokopiou (Inactive)
            aollebla@redhat.com Àngel Ollé Blázquez
            Paul Lodge Paul Lodge
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: