Skip to content

Remove possible false positive detection from nginx #1469

@Tbaile

Description

@Tbaile

The nginx fork provided in NethSecurity is not the most up to date, however it doesn't suffer from all the CVEs our customers provide. This is due to systems incorrectly flagging some versions only based off the server tokens. Additionally, some tools detect issues when some headers are not applied by default, this is wrong and need to be improved due to the fact that automatic tools should ring only when an actual vulnerability is found.
The planned solution is to document how to hide such banners.

Metadata

Metadata

Assignees

No one assigned

    Labels

    verifiedAll test cases were verified successfully

    Type

    Projects

    Status

    Verified

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions