3 ms·
This is considered a critical security vulnerability. [0] [0] https://owasp.org/www-project-top-ten/2017/A6_2017-Security_Misconfiguration https://owasp.org/ww
by karlerss 5y ago
This is considered a critical security vulnerability. [0]
[0] https://owasp.org/www-project-top-ten/2017/A6_2017-Security_Misconfiguration https://owasp.org/www-project-top-ten/2017/A6_2017-Security_...
- bullen 5y agoNot if it's open-source. Security by obfuscation is generally not a good option if you can avoid it.
- karlerss 5y agoIf there are other vulnerabilities present, stack traces can be forced to dump all sorts of data like env variables and network information and maybe someone else's personal information. I strongly urge everyone to hide their stack traces in production. This will reduce your application's attack surface.
- tester34 5y ago>Security by obfuscation is generally not a good option if you can avoid it. Of course, but obscurity increases security