Server information exposure

Unnecessary internal server information is exposed to clients.

Description

A server may expose unnecessary internal details to clients, including software versions, components and debug messages. Attackers can use this information to identify useful attack paths.

Potential impact

  • Attack preparation: Disclosed details can help an attacker locate weaknesses.
  • Exploitation: Software-version information may help identify known vulnerabilities.
  • Further compromise: When exploitable weaknesses also exist, the information may assist attacks against systems or data.

Remediation

  • Minimize server details in response headers and error messages.
  • Disable debug mode in production.
  • Configure the server and framework to avoid unnecessary disclosure.

Examples

These are application-configuration excerpts. Review debug responses separately from version headers set by servers and proxies. Django's HTTPS/HSTS settings require an HTTPS deployment and SecurityMiddleware configuration; Flask's REMEMBER_COOKIE_SECURE applies to Flask-Login remember cookies.

Django

Before

python
# Django with DEBUG enabled
from django.http import HttpResponse

def unsafe_view(request):
    return HttpResponse("Hello, world!")

# settings.py
DEBUG = True

After

python
# Django with DEBUG disabled
from django.http import HttpResponse

def safe_view(request):
    return HttpResponse("Hello, world!")

# settings.py
DEBUG = False
SECURE_CONTENT_TYPE_NOSNIFF = True
SECURE_HSTS_SECONDS = 3600
SECURE_HSTS_INCLUDE_SUBDOMAINS = True
SECURE_HSTS_PRELOAD = True
SECURE_SSL_REDIRECT = True
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True

Explanation:

  • Before: Debug mode may expose internal details in error responses.
  • After: Debug error responses are disabled. The remaining settings protect HTTPS and cookies; they do not automatically remove server-version headers.

Flask

Before

python
# Flask with DEBUG enabled
from flask import Flask

app = Flask(__name__)
app.config['DEBUG'] = True

@app.route('/')
def unsafe():
    return "Hello, world!"

After

python
# Flask with DEBUG disabled
from flask import Flask

app = Flask(__name__)
app.config['DEBUG'] = False
app.config['SESSION_COOKIE_SECURE'] = True
app.config['REMEMBER_COOKIE_SECURE'] = True

@app.route('/')
def safe():
    return "Hello, world!"

Explanation:

  • Before: Enabled debug mode may disclose internal information.
  • After: Debug responses are disabled and HTTPS cookie settings are applied. Check version headers separately in the web server and proxy.

FastAPI

Before

python
# FastAPI with debug mode enabled
from fastapi import FastAPI

app = FastAPI(debug=True)

@app.get("/")
async def unsafe():
    return {"message": "Hello, world!"}

After

python
# FastAPI with debug mode disabled
from fastapi import FastAPI

app = FastAPI(debug=False)

@app.get("/")
async def safe():
    return {"message": "Hello, world!"}

Explanation:

  • Before: Debug responses may expose internal information to clients.
  • After: Debug mode is disabled to reduce this disclosure.

References