Version Disclosure (Phusion Passenger)

Severity: Low

Invicti identified a version disclosure (Phusion Passenger) in the target web server's HTTP response. Phusion Passenger is a free web server and application server with support for Ruby, Python, and Node.js.

This information can help an attacker gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of Phusion Passenger.

An attacker might use the disclosed information to harvest specific security vulnerabilities for the version identified.

Configure Phusion Passenger to prevent version to prevent information leakage from X-Powered-By header by setting:

passenger_show_version_in_header off;

Build your resistance to threats. And save hundreds of hours each month.

Get a demo See how it works