You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In the ingress-nginx hardening guide, section 2.5.1 notes that "server_tokens is configured to off by default." Despite this, after testing a new install of ingress-nginx-controller v0.35.0, server-tokens appears to be enabled. Further, the ingress-nginx user guide notes that this default-enabled behavior is expected, which contradicts the hardening guide.
/kind bug
The text was updated successfully, but these errors were encountered:
Piccirello
changed the title
server_tokens directive is enabled by default on new installs
Security issue: server_tokens directive is enabled by default on new installs
Sep 15, 2020
In the ingress-nginx hardening guide, section 2.5.1 notes that "server_tokens is configured to off by default." Despite this, after testing a new install of ingress-nginx-controller v0.35.0, server-tokens appears to be enabled. Further, the ingress-nginx user guide notes that this default-enabled behavior is expected, which contradicts the hardening guide.
/kind bug
The text was updated successfully, but these errors were encountered: