Skip to content

Commit 9355011

Browse files
authored
Merge pull request #4122 from OpenLiberty/ZAP_report_fix
Zap report fix
2 parents 44c63d7 + 2e9368a commit 9355011

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

src/main/java/io/openliberty/website/SecurityFilter.java

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,9 @@ public void doFilter(ServletRequest req, ServletResponse resp, FilterChain chain
5959
} else if ("https".equals(req.getScheme())) {
6060
// If HTTPS is configured this sets a bunch of security headers
6161

62+
// Remove X-Powered-By header to prevent information disclosure (OWASP recommendation)
63+
response.setHeader("X-Powered-By", "");
64+
6265
// Tell browsers that this site should only be accessed using HTTPS, instead of using HTTP.
6366
// IncludeSubDomains and 1 year set per OWASP.
6467
response.setHeader("Strict-Transport-Security", "max-age=31536000; includeSubDomains");

0 commit comments

Comments
 (0)