Project

General

Profile

Actions

Bug #55

open

Epic #51: Security Points Checking

Story #42: Server Banner Disclosure

Server Banner Disclosure via HTTP Response Headers

Added by rashmita rout about 1 month ago.

Status:
New
Priority:
Medium
Target version:
-
Start date:
01/13/2026
Due date:
% Done:

0%

Estimated time:
Work Type:
Bug Fix
Technical Area:
Bug Origin:
Sprint
Customer Impact:
Planned Sprint:
Completed In Sprint:
Spillover Reason:

Description

The application discloses backend server technology and version information via HTTP response headers. The Server and X-Powered-By headers reveal details such as the web server software and its version. This information can be leveraged by attackers to fingerprint the technology stack and identify known vulnerabilities applicable to the disclosed versions.

Steps:-
Open the application in a browser.
Capture any HTTP/HTTPS request using Burp Suite or browser Developer Tools.
Inspect the HTTP response headers.
Observe that server technology and version details are exposed

Expected Result:-
The application should not disclose detailed server software or version information in HTTP response headers. Generic or removed headers should be used to prevent technology fingerprinting.

Actual Result:-
The application exposes web server and runtime version details in response headers, allowing attackers to identify the underlying technology stack

Please find the below link for reference:-
https://thehigherpitch-my.sharepoint.com/:i:/p/rashmita_rout/IQCnFfqFIkurSIk84GdkfWssAVVs5ufS1PYwjne0m8-xX4A?e=9sErvZ
https://thehigherpitch-my.sharepoint.com/:i:/p/rashmita_rout/IQDzAvvk094fQZ8ZV2FIp0u1AZI4ksKu9AJ5qvuY0pL9il8?e=yTgegB

No data to display

Actions

Also available in: Atom PDF