Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Misidentification of "Apache Coyote 1.1" #51

Open
epicfaace opened this issue Sep 10, 2020 · 1 comment
Open

Misidentification of "Apache Coyote 1.1" #51

epicfaace opened this issue Sep 10, 2020 · 1 comment

Comments

@epicfaace
Copy link
Contributor

epicfaace commented Sep 10, 2020

Intrigue ident misidentifies Apache Tomcat as "Apache Coyote 1.1". In fact, the "Apache-Coyote/1.1" "Server" header is only sent back from versions of Apache Tomcat from 4.1.x to 8.0.x (see https://tomcat.apache.org/tomcat-7.0-doc/security-howto.html).

I get a result such as the following:

cpe: "cpe:2.3:a:apache:coyote:1.1:"
hide: false
inference: true
issues: null
match_details: "Apache coyote application server - server header"
match_type: "content_headers"
method: "ident"
product: "Coyote"
tags: ["Application Server"]
0: "Application Server"
tasks: null
type: "fingerprint"
update: null
vendor: "Apache"
version: "1.1"
@jcran
Copy link
Member

jcran commented Oct 19, 2020

Sorry for the delayed response on this, we're looking into it and will get this addressed. Thank you @epicfaace!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants