Rule Name:Invalid Use of Identity in Content-Encoding Header
Severity:mid
CVE ID:
Descripiton:
Attakers may hack the Web server making use of HTTP. Refer to RFC2616: the use of no transformation whatsoever. This content-coding is used only in the Accept- Encoding header, and SHOULD NOT be used in the Content-Encoding header. This rule supports to defend the A1: Broken Access Control of OWASP Top 10 - 2021. Other reference:None