Hello How can we disable HTTP trace/track HTTP me...
# all-things-deployment
r
Hello How can we disable HTTP trace/track HTTP methods for datahub mae and mce. This is reported by our infosec team as one of the vulnerabilities. datahub version : v0.8.41
i
Hello @rich-policeman-92383 Could you provide some more information? Where do you see those methods?
r
Port 9090 and port 9091. These ports are bind with mae and mce on the nodes on which this vulnerability is reported. https://github.com/datahub-project/datahub/blob/master/docker/datahub-mae-consumer/Dockerfile#L53
i
Can you share some more information? Privately is fine.
r
I have privately shared a snippet of report shared by infosec.
Nessus is a proprietary vulnerability scanner offered by Tenable. The vulnerability reported is mentioned here : https://www.tenable.com/plugins/nessus/11213