You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
Yes, when there are no entries on a RSS feed, an automatic generator is inserted with shows EE and the exact version number.
This could be a data disclosure risk for some who have configured a template, forgotten about it and then have not upgraded allowing a malicious actor to exploit any unpatched issues.
Describe the solution you'd like
Removing the generator tag entirely or maybe just using "Expression Engine" instead of the version. I doubt there is much of a technical reason why the version is needed in this specific place.
Describe alternatives you've considered
Using the empty_feed option does work around but isn't one many would use I don't think for that specific outcome.
The text was updated successfully, but these errors were encountered:
Is your feature request related to a problem? Please describe.
Yes, when there are no entries on a RSS feed, an automatic generator is inserted with shows EE and the exact version number.
This could be a data disclosure risk for some who have configured a template, forgotten about it and then have not upgraded allowing a malicious actor to exploit any unpatched issues.
Describe the solution you'd like
Removing the generator tag entirely or maybe just using "Expression Engine" instead of the version. I doubt there is much of a technical reason why the version is needed in this specific place.
Describe alternatives you've considered
Using the
empty_feed
option does work around but isn't one many would use I don't think for that specific outcome.The text was updated successfully, but these errors were encountered: