AEM 6.5 on-premise Cache poisoning via malicious request header vulnerability
We have observed this vulnerability on our website built on AEM 6.5, Apache 2.4, cache enabled.
Cache poison via malicious request header
Server/Application Misconfiguration Cache poisoning
A cache poisoning vulnerability has been identified: issue at domain.com
The request header Handlechanges the response and is not part of the cache key, which means that this response is cached and will be served to other users on the site.
https://owasp.org/www-community/attacks/Cache_Poisoning
Anyone came across this? Appreciate any solutions around this.