Skip to content

Response Integrity Audit (Cache Poisoning & HPP)

response-integrity-audit is a medium severity check in the web category, written in yaml. Its source is templates/web/cache/response-integrity-audit.yaml in cert-x-gen-templates.

Audits response integrity for cache poisoning, HTTP parameter pollution, and header-injection exposure. Analyzes response size and content variations.

Field Value
Id response-integrity-audit
Severity medium
Language yaml
Category web
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 75
CVSS not recorded
Weakness CWE-444, CWE-113
Tags cache-poisoning, hpp, response-integrity, web-cache, parameter-pollution, web
Target kind not recorded
Oracle not recorded

The file declares http as well. Those are not tabled above; read the source for what they carry.

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info response-integrity-audit

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.