[DELETED, DUPLICATE OF 7.4.1]
Level 1 required: False
Level 2 required: False
Level 3 required: False
Verify that web or application server and application framework debug modes are disabled in production to eliminate debug features, developer consoles, and unintended security disclosures.
Level 1 required: True
Level 2 required: True
Level 3 required: True
CWE: 497
Verify that the HTTP headers or any part of the HTTP response do not expose detailed version information of system components.
Level 1 required: True
Level 2 required: True
Level 3 required: True
CWE: 200
Credit via OWASP ASVS. For more information visit The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v3.0 license.
Loading comments 0%