Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove EE default generator tag. #1139

Closed
iammattmartin opened this issue Jun 16, 2021 · 2 comments · Fixed by iammattmartin/ExpressionEngine#1 or #1189
Closed

Remove EE default generator tag. #1139

iammattmartin opened this issue Jun 16, 2021 · 2 comments · Fixed by iammattmartin/ExpressionEngine#1 or #1189
Labels
EE6 enhancement New feature or request

Comments

@iammattmartin
Copy link
Contributor

Is your feature request related to a problem? Please describe.
Yes, when there are no entries on a RSS feed, an automatic generator is inserted with shows EE and the exact version number.

This could be a data disclosure risk for some who have configured a template, forgotten about it and then have not upgraded allowing a malicious actor to exploit any unpatched issues.

Describe the solution you'd like
Removing the generator tag entirely or maybe just using "Expression Engine" instead of the version. I doubt there is much of a technical reason why the version is needed in this specific place.

Describe alternatives you've considered
Using the empty_feed option does work around but isn't one many would use I don't think for that specific outcome.

@intoeetive
Copy link
Contributor

@iammattmartin this sounds completely legit!
Would you be willing to submit a pull request with the generator line being removed to RSS module file?

@iammattmartin
Copy link
Contributor Author

Sure.

#1189

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
EE6 enhancement New feature or request
Projects
None yet
2 participants