Description
Cytrix has detected that information regarding your Apache status is being displayed.
Sensitive information such as the Apache status is being displayed on this page, causing Information Disclosure.
Attackers can use this information to conduct further, more advanced attacks against your assets.
Severity/Score
CVSS Version 3.x – 5.3 Medium
Recommendation
If this feature is not being used by you, disable it through the Apache config file.
You can simply disable “server-status”. Also, you can restrict access to the “/server-status” URL.
References
https://cwe.mitre.org/data/definitions/200.html
https://cytrix.io/blog/blog/information-disclosure-self-revealing-our-secrets/