-
Notifications
You must be signed in to change notification settings - Fork 53
TWA 0403
Ulrich Berntien edited this page Sep 6, 2020
·
3 revisions
"Environment file being served at: ${url}"
In the message output the variable ${url}
is replaced by the served URL of the environment file.
Files used to store Docker environment variables should not be published by the web server. A possible attacker should not get information of the internal settings of the web server.
Current (August 2020) the twa script checks the files: '.env' and '.dockerenv'.
Configure the web server to not publish files with internal data.
There exists several configuration options to suppress files with name (pattern) in a blacklist or files not in whitelist. Search the web for examples.