Bug ID 1239273: F5OS returns http server version in http header response

Last Modified: Aug 01, 2024

Affected Product(s):
F5OS None(all modules)

Known Affected Versions:
F5OS-A 1.3.0, F5OS-A 1.3.1, F5OS-A 1.3.2, F5OS-A 1.4.0, F5OS-A 1.5.0, F5OS-A 1.5.1, F5OS-A 1.5.2

Fixed In:
F5OS-A 1.7.0

Opened: Feb 13, 2023

Severity: 3-Major

Symptoms

F5OS is returning the internal http server version and type in http header response.

Impact

The http response header from F5OS contains the http server version and type which would be detected in security scans.

Conditions

Always.

Workaround

No workaround.

Fix Information

Suppressed http server verion from F5OS header response.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips