Version Disclosure (Phusion Passenger)

Severity: Low
Summary#

Invicti identified a version disclosure (Phusion Passenger) in the target web server's HTTP response. Phusion Passenger is a free web server and application server with support for Ruby, Python, and Node.js.

This information can help an attacker gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Phusion Passenger.

Impact#
An attacker might use the disclosed information to harvest specific security vulnerabilities for the version identified.
Remediation#

Configure Phusion Passenger to prevent version to prevent information leakage from X-Powered-By header by setting:

passenger_show_version_in_header off;

Invicti

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo