Uploaded image for project: 'Runtime'
  1. Runtime
  2. RUNTIME-4273

Version number should not be exposed publicly by the application

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Unresolved
    • Icon: Major Major
    • 4.9.5, 4.10.0
    • 4.9.4, 4.10.0
    • None
    • 4.10 M3

      Best practices advises against exposing version number in application to avoid displaying the potential vulnerability your are exposed to based on the version of the application and its components.

      The Ametys version should at least be restricted to authenticated user in BO (to be no worse than the information displayed in About).
      Version of component like Tomcat, Cocoon and such should probably never been exposed, but at least never in production mode.

            Unassigned Unassigned
            ggouin Guillaume Gouin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: