Skip to content
Ulrich Berntien edited this page Sep 6, 2020 · 3 revisions

TWA-0403

Message

"Environment file being served at: ${url}"

In the message output the variable ${url} is replaced by the served URL of the environment file.

Explanation

Files used to store Docker environment variables should not be published by the web server. A possible attacker should not get information of the internal settings of the web server.

Current (August 2020) the twa script checks the files: '.env' and '.dockerenv'.

Remediation

Configure the web server to not publish files with internal data.

There exists several configuration options to suppress files with name (pattern) in a blacklist or files not in whitelist. Search the web for examples.

Clone this wiki locally