We have ceph pacific installed as per security team VA scan they found “Web Server HTTP Header Internal IP Disclosure” CVE-2000-0649. To fix security team suggested to remove x-forwarder-for. As they have identified the port as 8443.
I suspect this is coming from ceph dashboard. I am not sure how to disable or how approach to find out responsible server or configuration file. can anyone help to mitigate this in ceph
I have check the ceph doc but there is no indication how to disable this.
Md Mustafizur Rahman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.