Description
Due to incorrect configuration, Enovy proxy discloses sensitive information about the target in the "x-envoy-peer-metadata" response header.
Remediation
Hide "x-envoy-peer-metadata" header
References
Related Vulnerabilities
Cloud metadata publicly exposed
WordPress Plugin Video Conferencing with Zoom Information Disclosure (3.8.16)
Unrestricted access to NGINX+ API interface (read only)
WordPress Plugin Aspose Cloud eBook Generator Arbitrary File Download (1.0)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3796)