Skip to content

Calling api/v1/version without valid token works #3556

Open
@cincuranet

Description

@cincuranet

I can call api/v1/version without valid token and I get back version. Is that expected? My expectation is that it should fail. Exposing freely the server version is small clue that attacker might find potentially useful.

Same for heartbeat call. But I don't have strong opinion on this (my general expectation would be that every endpoint requires auth, when auth is enabled).

Metadata

Metadata

Assignees

Labels

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions