Description
The Snoop Servlet returns information about the HTTP request itself and sometimes. It could help an attacker to prepare more advanced attacks
Remediation
Remove the Snoop Servlet from production systems or restrict access to it.
References
Related Vulnerabilities
WordPress Plugin SP Project & Document Manager Multiple Vulnerabilities (2.5.9.7)
Oracle Reports Services RWServlet environment variables disclosure
WordPress Plugin LearnDash LMS Multiple Information Disclosure Vulnerabilities (4.10.2)
TCExam Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-20114)