Typical severity: High. Likelihood of attack: Medium. An adversary manipulates and injects malicious content, in the form of secret unauthorized HTTP responses, into a single HTTP response from a vulnerable or compromised back-end HTTP agent (e.g., web server) or into an already spoofed HTTP response from an adversary controlled domain/site. See CanPrecede relationships for possible consequences.
Design: evaluate HTTP agents prior to deployment for parsing/interpretation discrepancies. | Configuration: front-end HTTP agents notice ambiguous requests. | Configuration: back-end HTTP agents reject ambiguous requests and close the network connection. | Configuration: Disable reuse of back-end connections. | Configuration: Use HTTP/2 for back-end connections.