Remove "server awselb/2.0" header from application responses
1
During a pentest of one of our apps running behind an AWS API GW the report showed that the API GW returns a "server awselb/2.0" header, which is identified as a risk by the pentesters. To my knowledge there is no way to remove/suppress such a header, but perhaps I am missing something? Is this something anybody else has ever faced?
asked 2 months ago124 views
1 Answers
Relevant questions
Lambda+ALB vs Lambda+API GW
Accepted Answerasked 6 months agoHandel custom header in AWS API Gateway ?
Accepted Answerasked 11 days agoReturn Count from Lambda into the "Response Header" of the API
Accepted Answerasked 2 years agoAPI GW HTTP API: Cross Account Access via IAM
asked 11 days agosecure API GW with WAF
asked 3 months agoCreate API GW Websocket API that is only accessible from within a VPC.
asked 2 months agoEdge optimized API GW
Accepted Answerasked a year agoProtect HTTP Api Gateway with WAF
asked 3 months agoRemove "server awselb/2.0" header from application responses
asked 2 months agoProtect and secure http API GW
Accepted Answerasked 3 months ago