Server Information Disclosure of Azure Gateway - Opinion Validation

Zenith Nandy 65 Reputation points
2025-11-18T06:21:34.5+00:00

This question refers https://learn.microsoft.com/en-us/answers/questions/5625233/justification-against-server-information-disclosur, and I am asking it again with some modification since I didn't get the response in the way I wanted.

Scenario:

Our application is hosted in the Azure environment. A recent security scan flagged the response header Server: Microsoft-Azure-Application-Gateway/v2 as a “Server Information Disclosure” issue, stating that exposing the version identifier (“v2”) may reveal sensitive server details.

Intention and Observation:

I had already read about the header rewrite rules and the numerous other discussion threads where users were trying to configure the response header settings. My intention is a bit different here.

I don’t intend to rewrite the rules, as I believe no sensitive information about the application or server is exposed simply by the presence of “Microsoft-Azure-Application-Gateway/v2” or the version indicator “v2”. A justification from your side regarding the same would help.

Expectation:

I am just trying to get my opinion validated here. Please do not provide the entire details of rewriting the header rules.

So once again, I basically have two asks.

  1. Is it an actual security vulnerability if I keep the response header as it is and don't fiddle with it ?
  2. If not, can you please enlighten on what "v2" signifies in Azure Gateway and is it ok if "v2" comes in the "Server" header of the response ? As the scan has flagged "v2" as the version number of the server (similar to software versions, ex- Google Chrome's version 142.0.7444.163)
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.