Description
A server may expose unnecessary internal details to clients, including software versions, components and debug messages. Attackers can use this information to identify useful attack paths.
Potential impact
- Attack preparation: Disclosed details can help an attacker locate weaknesses.
- Exploitation: Software-version information may help identify known vulnerabilities.
- Further compromise: When exploitable weaknesses also exist, the information may assist attacks against systems or data.
Remediation
- Minimize server details in response headers and error messages.
- Disable debug mode in production.
- Configure the server and framework to avoid unnecessary disclosure.
Examples
These are application-configuration excerpts. Review debug responses separately from version headers set by servers and proxies. Django's HTTPS/HSTS settings require an HTTPS deployment and SecurityMiddleware configuration; Flask's REMEMBER_COOKIE_SECURE applies to Flask-Login remember cookies.
Django
Before
python
# Django with DEBUG enabled
from django.http import HttpResponse
def unsafe_view(request):
return HttpResponse("Hello, world!")
# settings.py
DEBUG = True
After
python
# Django with DEBUG disabled
from django.http import HttpResponse
def safe_view(request):
return HttpResponse("Hello, world!")
# settings.py
DEBUG = False
SECURE_CONTENT_TYPE_NOSNIFF = True
SECURE_HSTS_SECONDS = 3600
SECURE_HSTS_INCLUDE_SUBDOMAINS = True
SECURE_HSTS_PRELOAD = True
SECURE_SSL_REDIRECT = True
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True
Explanation:
- Before: Debug mode may expose internal details in error responses.
- After: Debug error responses are disabled. The remaining settings protect HTTPS and cookies; they do not automatically remove server-version headers.
Flask
Before
python
# Flask with DEBUG enabled
from flask import Flask
app = Flask(__name__)
app.config['DEBUG'] = True
@app.route('/')
def unsafe():
return "Hello, world!"
After
python
# Flask with DEBUG disabled
from flask import Flask
app = Flask(__name__)
app.config['DEBUG'] = False
app.config['SESSION_COOKIE_SECURE'] = True
app.config['REMEMBER_COOKIE_SECURE'] = True
@app.route('/')
def safe():
return "Hello, world!"
Explanation:
- Before: Enabled debug mode may disclose internal information.
- After: Debug responses are disabled and HTTPS cookie settings are applied. Check version headers separately in the web server and proxy.
FastAPI
Before
python
# FastAPI with debug mode enabled
from fastapi import FastAPI
app = FastAPI(debug=True)
@app.get("/")
async def unsafe():
return {"message": "Hello, world!"}
After
python
# FastAPI with debug mode disabled
from fastapi import FastAPI
app = FastAPI(debug=False)
@app.get("/")
async def safe():
return {"message": "Hello, world!"}
Explanation:
- Before: Debug responses may expose internal information to clients.
- After: Debug mode is disabled to reduce this disclosure.
References
- OWASP: Information Exposure
- CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE: CWE-209: Generation of Error Message Containing Sensitive Information
- CWE: CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
- Django 4.0 removal of the X-XSS-Protection setting