The remote Debian host is missing a security-related update.
It was discovered that incomplete validation in a Phar processing library embedded in Drupal, a fully-featured content management framework, could result in information disclosure. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2019-007.
Upgrade the drupal7 packages. For the stable distribution (stretch), this problem has been fixed in version 7.52-2+deb9u9.