That's an interesting attack vector, in the section 3 of the RFC they recommend to ignore the directive unless it's a secure connection which would mitigate that kind of problems.
Another solution would be to use an unpredictable versioning scheme so the attacker can't anticipate the name of the resources.