Server Information Disclosure of Azure Gateway - Opinion Validation
This question refers https://learn.microsoft.com/en-us/answers/questions/5625233/justification-against-server-information-disclosur, and I am asking it again with some modification since I didn't get the response in the way I wanted.
Scenario:
Our application is hosted in the Azure environment. A recent security scan flagged the response header Server: Microsoft-Azure-Application-Gateway/v2 as a “Server Information Disclosure” issue, stating that exposing the version identifier (“v2”) may reveal sensitive server details.
Intention and Observation:
I had already read about the header rewrite rules and the numerous other discussion threads where users were trying to configure the response header settings. My intention is a bit different here.
I don’t intend to rewrite the rules, as I believe no sensitive information about the application or server is exposed simply by the presence of “Microsoft-Azure-Application-Gateway/v2” or the version indicator “v2”. A justification from your side regarding the same would help.
Expectation:
I am just trying to get my opinion validated here. Please do not provide the entire details of rewriting the header rules.
So once again, I basically have two asks.
- Is it an actual security vulnerability if I keep the response header as it is and don't fiddle with it ?
- If not, can you please enlighten on what "v2" signifies in Azure Gateway and is it ok if "v2" comes in the "Server" header of the response ? As the scan has flagged "v2" as the version number of the server (similar to software versions, ex- Google Chrome's version 142.0.7444.163)