How to Hide the Tomcat Version Shown on Error Pages #7613
Unanswered
amarantmeida
asked this question in
FAQs
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
A security scan reported that the server is exposing Tomcat details on the default error page. When accessing an invalid or malformed URL (for example: / %20 /), the browser shows a Tomcat-generated 404 page, including:
This is flagged as
Improper Error Handlingbecause it reveals internal server information.Sharing this here so the team can confirm the correct approach to hide or mask these details, and so others who see the same scan results know how to handle it.
Beta Was this translation helpful? Give feedback.
All reactions