<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynatrace should be configured to prevent disclosure of web component and configuration information in the body web pages in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/Dynatrace-should-be-configured-to-prevent-disclosure-of-web/m-p/185232#M20668</link>
    <description>&lt;P&gt;The versions of web components were revealed in the source code files of the Dynatrace application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following list details the source code files where versions of web components were revealed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;jQuery 3.2.0
&lt;UL&gt;
&lt;LI&gt;/ruxit/cache/js/lib/jquery-3.2.0.min.js&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;d3 Version 4.12.0
&lt;UL&gt;
&lt;LI&gt;/ruxit/cache/js/lib/d3-4.12.0.min.js&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Highcharts JS v6.2.0 (2018-10-17)
&lt;UL&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-export-data-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-exporting-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-heatmap-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-more-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-offline-exporting-6.2.0.js&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;topojson Version 2.2.0
&lt;UL&gt;
&lt;LI&gt;/ruxit/cache/js/lib/topojson-2.2.0.min.js&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Implications&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The exposure of configuration information provides an attacker information regarding the server. This information may allow an attacker to work with when crafting exploits for the system and increases the risk of the system being compromised.&lt;/P&gt;
&lt;P&gt;Allowing unnecessary information disclosure relating to web component versions can allow an attacker to identify specific vulnerabilities or exploits for the system and increase the risk of the system being compromised.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 11:37:42 GMT</pubDate>
    <dc:creator>isaace</dc:creator>
    <dc:date>2022-10-19T11:37:42Z</dc:date>
    <item>
      <title>Dynatrace should be configured to prevent disclosure of web component and configuration information in the body web pages</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Dynatrace-should-be-configured-to-prevent-disclosure-of-web/m-p/185232#M20668</link>
      <description>&lt;P&gt;The versions of web components were revealed in the source code files of the Dynatrace application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following list details the source code files where versions of web components were revealed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;jQuery 3.2.0
&lt;UL&gt;
&lt;LI&gt;/ruxit/cache/js/lib/jquery-3.2.0.min.js&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;d3 Version 4.12.0
&lt;UL&gt;
&lt;LI&gt;/ruxit/cache/js/lib/d3-4.12.0.min.js&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Highcharts JS v6.2.0 (2018-10-17)
&lt;UL&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-export-data-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-exporting-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-heatmap-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-more-6.2.0.js&lt;/LI&gt;
&lt;LI&gt;/ruxit/cache/js/lib/highcharts-offline-exporting-6.2.0.js&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;topojson Version 2.2.0
&lt;UL&gt;
&lt;LI&gt;/ruxit/cache/js/lib/topojson-2.2.0.min.js&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Implications&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The exposure of configuration information provides an attacker information regarding the server. This information may allow an attacker to work with when crafting exploits for the system and increases the risk of the system being compromised.&lt;/P&gt;
&lt;P&gt;Allowing unnecessary information disclosure relating to web component versions can allow an attacker to identify specific vulnerabilities or exploits for the system and increase the risk of the system being compromised.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 11:37:42 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Dynatrace-should-be-configured-to-prevent-disclosure-of-web/m-p/185232#M20668</guid>
      <dc:creator>isaace</dc:creator>
      <dc:date>2022-10-19T11:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace should be configured to prevent disclosure of web component and configuration information in the body web pages - Status changed to: Under review</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Dynatrace-should-be-configured-to-prevent-disclosure-of-web/m-p/185235#M20669</link>
      <description>&lt;P&gt;Checking with the team.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:37:01 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Dynatrace-should-be-configured-to-prevent-disclosure-of-web/m-p/185235#M20669</guid>
      <dc:creator>Radoslaw_Szulgo</dc:creator>
      <dc:date>2022-04-21T12:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace should be configured to prevent disclosure of web component and configuration information in the body web pages</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Dynatrace-should-be-configured-to-prevent-disclosure-of-web/m-p/185247#M20670</link>
      <description>&lt;DIV id="C7HNN4YR1-1650544583.962829-thread-list-threads-flexpane_1650548148.747479" class="c-virtual_list__item c-virtual_list__item--initial-activeitem" tabindex="0" role="listitem" data-qa="virtual-list-item"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__background--hovered c-message_kit__background--highlight c-message_kit__message c-message_kit__thread_message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover c-message_kit__hover--hovered" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--default"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;It’s a known issue and nothing to be fixed. There is no point in removing the versions from the file names because we’d also need to get rid of the comments and even then it’s quite easy to determine version by searching by the source itself&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 21 Apr 2022 13:37:29 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Dynatrace-should-be-configured-to-prevent-disclosure-of-web/m-p/185247#M20670</guid>
      <dc:creator>Radoslaw_Szulgo</dc:creator>
      <dc:date>2022-04-21T13:37:29Z</dc:date>
    </item>
  </channel>
</rss>

