Back to Gitlabhq

X-Backend-Server header exposes server information

doc/user/application_security/dast/browser/checks/16.4.md

18.11.2593 B
Original Source

Description

The target website returns the X-Backend-Server header which includes potentially internal/hidden IP addresses or hostnames. By exposing these values, attackers may attempt to circumvent security proxies and access these hosts directly.

Remediation

Consult your proxy/load balancer documentation or provider on how to disable revealing the X-Backend-Server header value.

Details

IDAggregatedCWETypeRisk
16.4true16PassiveInfo