Skip to content

Magento 2.4.7-p1 exposes server information in HTTP response headers even in production mode — how to disable this?

I’m running a Magento 2.4.7-p1 store in production mode on an Ubuntu + Apache setup (hosted via Cloudways). During a recent security audit, a vulnerability was flagged under “Improper Error Handling / Information Disclosure.” The issue is that even when… Read More »Magento 2.4.7-p1 exposes server information in HTTP response headers even in production mode — how to disable this?