Krishna Pandey created ZEPPELIN-2461:
----------------------------------------

             Summary: Masking Jetty Server version with User-configurable 
parameter
                 Key: ZEPPELIN-2461
                 URL: https://issues.apache.org/jira/browse/ZEPPELIN-2461
             Project: Zeppelin
          Issue Type: Bug
          Components: Core
    Affects Versions: 0.7.0
         Environment: All
            Reporter: Krishna Pandey
            Priority: Minor


Security conscious organisations does not want to reveal the Application Server 
name and version to prevent Script-kiddies from finding the information easily 
when fingerprinting the Application. The exact version number can tell an 
Attacker if the current Application Server is patched for or vulnerable to 
certain publicly known CVE associated to it.



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

Reply via email to